Bug 2451432 (CVE-2026-1001)
| Summary: | CVE-2026-1001 Domoticz: Domoticz: Arbitrary script execution via stored cross-site scripting in web interface | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Domoticz. This stored cross-site scripting (XSS) vulnerability allows authenticated administrators to execute arbitrary scripts. By supplying crafted names containing script or HTML markup in the 'Add Hardware' and 'rename device' functionalities, attackers can inject malicious code. This code is then stored and rendered without proper output encoding, leading to script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2451506, 2451507, 2451508, 2451509 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-03-25 19:01:56 UTC
|