Unblu

Spark

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 22.07.2026 12:21:28
  • Zuletzt bearbeitet 22.07.2026 19:17:14

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host applic...

  • EPSS 0.23%
  • Veröffentlicht 22.04.2025 08:49:56
  • Zuletzt bearbeitet 23.06.2025 19:22:37

It technically possible for a user to upload a file to a conversation despite the file upload functionality being disabled. The file upload functionality can be enabled or disabled for specific use cases through configuration. In case the functional...