CVE-2025-8535 | cronoh NanoVault up to 1.2.1 xrb URL /main.js executeJavaScript cross site scripting (EUVD-2025-23580)
A vulnerability labeled as problematic has been found in cronoh NanoVault up to 1.2.1. Impacted is the function executeJavaScript of the file /main.js of the component xrb URL Handler. Executing manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2025-8535. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.