
CVE-2025-6024 The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by inj… https://www.cve.org/CVERecord?id=CVE-2025-6024
Post summary
The CVE discloses an XSS vulnerability in the authentication endpoint due to missing input encoding, but no PoC, exploit, active exploitation, or patch information is provided.
