Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NElastic App Search
APPElastic< 7.7.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
Related vulnerabilities
CVE-2021-22140HIGH7.5same product
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE...
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓same vendor
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2015-1427CRITICAL9.8⚠ KEVPL ✓same vendor
Elasticsearch: ucieczka z sandboksa Groovy i zdalne wykonanie poleceń
CVE-2025-37729CRITICAL9.1PL ✓same vendor
Elastic Cloud Enterprise — Server-Side Template Injection (SSTI) w silniku Jinjava
CVE-2025-25014CRITICAL9.1PL ✓same vendor
Prototype Pollution w Kibana prowadzące do RCE przez HTTP