CVE-2025-9096 | ExpressGateway express-gateway up to 1.16.10 REST Endpoint lib/rest/routes/apps.js cross site scripting (EUVD-2025-25106)
A vulnerability classified as problematic has been found in ExpressGateway express-gateway up to 1.16.10. This impacts an unknown function in the library lib/rest/routes/apps.js of the component REST Endpoint. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-9096. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.