This issue was fixed in 4.6.7.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Politechnika Warszawska
Politechnika Warszawska omega-psir |
|
| Vendors & Products |
Politechnika Warszawska
Politechnika Warszawska omega-psir |
Fri, 27 Feb 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pw
Pw omega-psir |
|
| CPEs | cpe:2.3:a:pw:omega-psir:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pw
Pw omega-psir |
|
| Metrics |
cvssV3_1
|
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7. | |
| Title | Reflected XSS in Omega-PSIR | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-02-27T15:38:38.137Z
Reserved: 2026-01-26T13:19:10.279Z
Link: CVE-2026-1434
Updated: 2026-02-27T15:38:33.647Z
Status : Analyzed
Published: 2026-02-27T11:16:04.770
Modified: 2026-02-27T17:34:25.750
Link: CVE-2026-1434
No data.
OpenCVE Enrichment
Updated: 2026-04-17T14:15:21Z