Vulnerabilities (CVE)

Filtered by vendor Gainsight Subscribe
Filtered by product Assist
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-31381 1 Gainsight 1 Assist 2026-04-16 N/A 5.3 MEDIUM
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.
CVE-2026-31382 1 Gainsight 1 Assist 2026-04-16 N/A 6.1 MEDIUM
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.