Medium severity5.6NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026
CVE-2025-50985
CVE-2025-50985
Description
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML response, allowing attackers to inject and execute arbitrary JavaScript when a victim visits a maliciously crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- diskover-web/diskover-web Community Editiondescription
- Range: = 2.3.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.