Bug 2512665 (CVE-2026-11425)
| Summary: | CVE-2026-11425 Domoticz: Domoticz: Stored cross-site scripting allows administrator account takeover | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Domoticz. An authenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability in the mobile dashboard. This allows the attacker to inject malicious code by updating specific device values through the application's programming interface (API). When an administrator views the mobile dashboard, this malicious code executes in their browser, which could lead to the theft of their session information and ultimately, account takeover.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-07 20:31:15 UTC
|