CVE-2025-32951 | Jmix up to 1.6.1/2.3.4 Header Content-Type cross site scripting (GHSA-x27v-f838-jh93)
A vulnerability, which was classified as problematic, has been found in Jmix up to 1.6.1/2.3.4. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument Content-Type leads to cross site scripting.
The identification of this vulnerability is CVE-2025-32951. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.