GHSA-j9f7-pmc4-vm2cMedium

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.

🔗 References (5)