Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Userspice
Userspice userspice |
|
| Vendors & Products |
Userspice
Userspice userspice |
Sat, 23 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | userSpice 4.3.24 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the X-Forwarded-For HTTP header. Attackers can send crafted requests to the backup.php endpoint with XSS payloads in the X-Forwarded-For header that execute when administrators visit the audit log page. | |
| Title | userSpice 4.3.24 Cross-Site Scripting via X-Forwarded-For Header | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-27T16:10:22.223Z
Reserved: 2026-05-23T15:33:04.251Z
Link: CVE-2018-25349
Updated: 2026-05-27T16:10:17.055Z
Status : Deferred
Published: 2026-05-23T19:16:54.987
Modified: 2026-06-17T01:55:17.523
Link: CVE-2018-25349
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:28Z