CVE-2025-5990 - Crafty Controller Stored XSS Vulnerability




CVE ID : CVE-2025-5990
Published : June 15, 2025, 6:15 p.m. | 55 minutes ago
Description : An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
Severity: 7.6 | HIGH

Comments

Popular posts from this blog

CVE-2026-17434 - nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization