CVE-2025-27412: REDAXO allows Authenticated Reflected Cross Site Scripting - packages installation
Reflected cross-site scripting (XSS) is a type of web vulnerability that occurs when a web application fails to properly sanitize user input, allowing an attacker to inject malicious code into the application’s response to a user’s request. When the user’s browser receives the response, the malicious code is executed, potentially allowing the attacker to steal sensitive information or take control of the user’s account.
References
Detect and mitigate CVE-2025-27412 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →