CVE-2025-50986 | diskover-web Community Edition 2.3.0 Administrative Settings Interface cross site scripting
A vulnerability classified as problematic has been found in diskover-web Community Edition 2.3.0. Impacted is an unknown function of the component Administrative Settings Interface. Performing manipulation of the argument ES_HOST/ES_INDEXREFRESH/ES_PORT/ES_SCROLLSIZE/ES_TRANSLOGSIZE/ES_TRANSLOGSYNCINT/EXCLUDES_FILES/FILE_TYPES[]/INCLUDES_DIRS/INCLUDES_FILES/TIMEZONE results in cross site scripting.
This vulnerability is cataloged as CVE-2025-50986. It is possible to initiate the attack remotely. There is no exploit available.