CVE-2025-49191: Dashboards and iFrames can link malicious web content
Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49191?
The severity of CVE-2025-49191 is rated as medium with a score of 6.1.
How do I fix CVE-2025-49191?
To fix CVE-2025-49191, ensure that only trusted URLs are used when creating iFrame widgets and dashboards.
What type of attack is associated with CVE-2025-49191?
CVE-2025-49191 is associated with a code execution attack that can affect users accessing compromised dashboard content.
Which software is impacted by CVE-2025-49191?
CVE-2025-49191 impacts SICK Field Analytics by allowing malicious content through iFrame widgets.
What are the attack vectors for CVE-2025-49191?
The primary attack vector for CVE-2025-49191 involves authorized users embedding malicious URLs in iFrame widgets.