CVE-2025-66022 | factionsecurity faction up to 1.7.0 Endpoint AppStoreDashboard inclusion of functionality from untrusted control sphere (GHSA-xr72-2g43-586w)
A vulnerability was found in factionsecurity faction up to 1.7.0 and classified as critical. This impacts an unknown function of the file /portal/AppStoreDashboard of the component Endpoint. The manipulation results in inclusion of functionality from untrusted control sphere.
This vulnerability is known as CVE-2025-66022. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.