An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
2025-06-16T10:15:19.517
2025-11-21T12:15:46.477
Awaiting Analysis
CVSSv3.1: 6.5 (MEDIUM)
-