PT-2026-26213 · Avo · Avo

Timwis

·

Published

2026-03-18

·

Updated

2026-03-24

·

CVE-2026-33209

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Avo versions prior to 3.30.3
Description A reflected cross-site scripting (XSS) issue exists in the return to query parameter within the Avo interface. An attacker can create a malicious URL that injects arbitrary JavaScript. This JavaScript is executed when a dynamically generated navigation button is clicked. The impact of this issue varies depending on the deployment configuration, potentially allowing the execution of arbitrary JavaScript in the context of the application. In unauthenticated setups, exploitation is possible through crafted links sent to users. In authenticated setups, exploitation is limited to authenticated users and requires interaction.
Recommendations Update to Avo version 3.30.3 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33209
GHSA-762R-27W2-Q22J

Affected Products

Avo