CVE-2026-90528 | TDuckApp tduck-platform up to 5.3 Form Write View index.vue submitShowCustomPageContent cross site scripting (IK5RJD)
A vulnerability, which was classified as problematic, has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting.
This vulnerability is tracked as CVE-2026-90528. The attack is possible to be carried out remotely. No exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.