Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-11425

Опубликовано: 07 авг. 2026
Источник: redhat
CVSS3: 7.7

Описание

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.

A flaw was found in Domoticz. An authenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability in the mobile dashboard. This allows the attacker to inject malicious code by updating specific device values through the application's programming interface (API). When an administrator views the mobile dashboard, this malicious code executes in their browser, which could lead to the theft of their session information and ultimately, account takeover.

Отчет

Exploitation requires low-privileged API access to push malicious scripts into device payload fields, which subsequently execute in an administrator's browser upon accessing the mobile dashboard, potentially compromising administrative session confidentiality and system integrity. This vulnerability strictly impacts Confidentiality and Integrity with zero impact on Availability as it does not disrupt service operation. Environments operating without mobile dashboard usage or where device updating APIs are strictly restricted to trusted internal networks remain unaffected.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the Domoticz API and mobile dashboard to trusted internal networks only. If the mobile dashboard functionality is not required, consider disabling or restricting access to it to prevent exploitation.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2512665Domoticz: Domoticz: Stored cross-site scripting allows administrator account takeover

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
12 дней назад

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.

CVSS3: 4.4
debian
12 дней назад

Domoticz versions prior to 2026.3 contains a stored cross-site scripti ...

CVSS3: 4.4
github
12 дней назад

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript by updating Text or Alert subtype device values through the API. The mobile dashboard renders device data via ng-bind-html with only an nl2br() transform that performs no HTML escaping, allowing attackers to store malicious payloads that execute in any administrator's browser upon viewing the mobile dashboard, enabling session cookie theft and account takeover.

7.7 High

CVSS3