CVE-2025-22491

The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting Software (FRS) application which could lead into execution of arbitrary JavaScript in a browser context for all the interacting users. This security issue has been patched in the latest version 1.5.100 of the FRS.
Configurations

No configuration.

History

26 Aug 2025, 11:15

Type Values Removed Values Added
Summary
  • (es) La entrada del usuario no se limpió en la página de administración de jerarquía de informes de la aplicación Foreseer Reporting Software (FRS), lo que podría provocar la ejecución de JavaScript arbitrario en un contexto de navegador para todos los usuarios que interactuaban. Este problema de seguridad se ha corregido en la última versión 1.5.100 de FRS.
CWE CWE-20 CWE-79

28 Feb 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-28 09:15

Updated : 2025-08-26 11:15


NVD link : CVE-2025-22491

Mitre link : CVE-2025-22491

CVE.ORG link : CVE-2025-22491


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')