Security Advisory

CVE-2025-11146

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-09-29 09:26:35
Last updated 2025-09-29 11:18:24
Assigner INCIBE
CVSS score 5.1
State PUBLISHED

Description

Reflected Cross-site scripting (XSS) in Apt-Cacher-NG v3.2.1. The vulnerability allows an attacker to execute malicious scripts (XSS) in the web management application. The vulnerability is caused by improper handling of GET inputs included in the URL in “/acng-report.html”.