PT-2025-40975 · Jakowenko · Jakowenko Double-Take
Omega3663
·
Published
2025-10-07
·
Updated
2025-10-07
·
CVE-2025-11360
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
jakowenko double-take versions up to 1.13.1
Description
A flaw exists in the API component of jakowenko double-take. The issue is related to the
app.use function within the api/src/app.js file. Manipulation of the X-Ingress-Path argument can lead to cross-site scripting. This attack can be carried out remotely.Recommendations
Upgrade to version 1.13.2 or later to resolve this issue.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jakowenko Double-Take