CVE-2026-5297

medium

Description

The vulnerability exists due to improper input sanitization parameters applied to the global search engine query fields. This allows an authenticated attacker to inject malicious strings, executing arbitrary cross-site scripting (XSS) actions inside other users' sessions.

Details

Source: Mitre, NVD

Published: 2026-05-14

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium