Untriaged
Permalink
CVE-2026-5301
7.6 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): HIGH
- Availability impact (A): LOW
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontrol-ui
Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries
References
Affected products
coolercontrol-ui
- <4.0.0
Package maintainers
-
@codifryed Guy Boldon <gb@guyboldon.com>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>