Critical Vulnerability Information CVE ID CVE-2025-50985 Vulnerability Description Multiple reflected Cross-Site Scripting (XSS) vulnerabilities exist in diskover-web v2.3.0 Community Edition. Unfiltered GET parameters (including , , , , , and ) are directly echoed into HTML responses, allowing attackers to inject and execute arbitrary JavaScript code via maliciously crafted URLs. Example URLs maxage - maxindex - index - - Cookie - Parameters: , Cookie JSON Parameters - , , , , Affected Versions diskover-web v2.3.0 Community Edition (ce) Exploitation Method Attackers can craft URLs containing malicious JavaScript code. When victims access these URLs, their browsers execute the malicious scripts, enabling a Cross-Site Scripting (XSS) attack.