A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.digi.com/resources/security |
Configurations
No configuration.
History
07 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-07 15:16
Updated : 2026-07-13 17:16
NVD link : CVE-2026-12948
Mitre link : CVE-2026-12948
CVE.ORG link : CVE-2026-12948
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
