Loading HuntDB...

GHSA-gv24-vhxm-xr5j

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulnerability in versions prior to 2.6.6 that could allow JavaScript code to be executed in the user's web browser if a specially crafted link is visited. The JavaScript code is executed on the user's system, not executed on LXCA itself.

Related CVEs

Key Information

GHSA ID
GHSA-gv24-vhxm-xr5j
Published
May 24, 2022 5:09 PM
Last Modified
May 24, 2022 5:09 PM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.