Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
| Software | From | Fixed in |
|---|---|---|
| agora-project / agora-project | - | 25.10 |