PT-2026-32518 · Dbgate · Dbgate
Ngocnn97
·
Published
2026-04-13
·
Updated
2026-04-14
·
CVE-2026-6216
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
DbGate versions prior to 7.1.5
Description
A cross-site scripting issue exists in the SVG Icon String Handler component within the file
packages/web/src/icons/FontIcon.svelte. Remote manipulation of the applicationIcon argument can lead to this issue.Recommendations
Upgrade to version 7.1.5.
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dbgate