allows an authorized attacker to plant arbitrary JavaScript code in the page
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://hub.ntc.swiss/ntcf-2025-7724 |
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant arbitrary JavaScript code in the page | |
| Title | Cross-Site Scripting Vulnerability in QWC2 Registration GUI | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2025-10-14T15:05:15.769Z
Reserved: 2025-09-30T06:08:22.823Z
Link: CVE-2025-11184
Updated: 2025-10-14T15:05:12.233Z
Status : Deferred
Published: 2025-10-13T10:15:46.123
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11184
No data.
OpenCVE Enrichment
No data.