VYPR
Unrated severityNVD Advisory· Published Feb 20, 2026· Updated Apr 7, 2026

OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation

CVE-2019-25448

Description

OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the name parameter. Attackers can send POST requests to the document endpoint with JavaScript code in the name field to execute arbitrary scripts when users view the application.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.