Loading product vulnerabilities…
Total
2
Critical
0
High
1
Medium
1
CISA KEV
0
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.