Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/emoncms/emoncms/issues/1940 |
|
History
Tue, 28 Oct 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openenergymonitor
Openenergymonitor emoncms |
|
| CPEs | cpe:2.3:a:openenergymonitor:emoncms:11.7.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Openenergymonitor
Openenergymonitor emoncms |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emoncms
Emoncms emoncms |
|
| Vendors & Products |
Emoncms
Emoncms emoncms |
Fri, 24 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated attackers with API access to inject malicious JavaScript code that executes when administrators view the application logs. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-24T16:31:03.976Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60936
Updated: 2025-10-24T16:30:59.904Z
Status : Analyzed
Published: 2025-10-24T15:15:40.440
Modified: 2025-10-28T02:32:52.333
Link: CVE-2025-60936
No data.