CVE-2026-12948

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA allows a remote, authenticated administrator to inject script into certain system configuration fields. The script subsequently executes in the browser of a user who views the affected pages (CWE-79).
CVSS

No CVSS.

References
Configurations

No configuration.

History

07 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 15:16

Updated : 2026-07-13 17:16


NVD link : CVE-2026-12948

Mitre link : CVE-2026-12948

CVE.ORG link : CVE-2026-12948


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')