Metrics
Affected Vendors & Products
Fri, 12 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Metaclinic
         Metaclinic nanovault  | 
|
| CPEs | cpe:2.3:a:metaclinic:nanovault:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Metaclinic
         Metaclinic nanovault  | 
Tue, 05 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 05 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Cronoh
         Cronoh nanovault  | 
|
| Vendors & Products | 
        
        Cronoh
         Cronoh nanovault  | 
Tue, 05 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | cronoh NanoVault xrb URL main.js executeJavaScript cross site scripting | |
| Weaknesses | CWE-79 CWE-94  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV2_0
         
 
 
 
  | 
Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-05T00:02:06.159Z
Updated: 2025-08-05T14:57:12.269Z
Reserved: 2025-08-04T12:01:02.830Z
Link: CVE-2025-8535
Updated: 2025-08-05T14:57:02.601Z
Status : Analyzed
Published: 2025-08-05T01:15:43.157
Modified: 2025-09-12T16:04:38.980
Link: CVE-2025-8535
No data.