Description
A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker. | |
| Title | Reflected Cross-Site Scripting in Dashboard Search | |
| First Time appeared |
Vertigis
Vertigis vertigis Fm |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:vertigis:vertigis_fm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vertigis
Vertigis vertigis Fm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-04-01T13:33:40.924Z
Reserved: 2026-03-10T12:01:10.709Z
Link: CVE-2026-3877
Updated: 2026-04-01T13:33:23.711Z
Status : Awaiting Analysis
Published: 2026-04-01T14:16:58.130
Modified: 2026-04-01T14:23:37.727
Link: CVE-2026-3877
No data.
OpenCVE Enrichment
No data.
Weaknesses