CVE-2025-28380: XSS
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28380?
CVE-2025-28380 is classified as a high-severity vulnerability due to its potential for allowing attackers to execute arbitrary web scripts.
How do I fix CVE-2025-28380?
To fix CVE-2025-28380, it is recommended to sanitize URL parameters and update to a patched version of OpenC3 COSMOS if available.
What systems are affected by CVE-2025-28380?
CVE-2025-28380 affects OpenC3 COSMOS version 6.0.0.
What kind of attacks can be performed using CVE-2025-28380?
Attackers can exploit CVE-2025-28380 to execute cross-site scripting (XSS) attacks by injecting malicious scripts via the URL parameter.
Is there a known exploit for CVE-2025-28380?
While specific exploits may not be publicly disclosed, the nature of CVE-2025-28380 makes it a candidate for exploitation in XSS scenarios.