MEDIUM🇵🇱 Wersja polska

CVE-2025-49193

CVSS 4.2v3.1pub. 2025-06-12upd. 2026-01-26

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Sick Baggage Analytics

    APP
    Sick
    all versions
  • Sick Field Analytics

    APP
    Sick
    all versions
  • Sick Logistic Diagnostic Analytics

    APP
    Sick
    all versions
  • Sick Media Server

    APP
    Sick
    < 1.5
  • Sick Package Analytics

    APP
    Sick
    all versions
  • Sick Tire Analytics

    APP
    Sick
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-2076CRITICAL9.8PL ✓same product

Obejście uwierzytelniania w SICK Package Analytics przez REST API

CVE-2025-49183HIGH7.5same product

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between a...

CVE-2025-49181HIGH8.6same product

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensi...

CVE-2025-49182HIGH7.5same product

Files in the source code contain login credentials for the admin user and the property configuration password,...

CVE-2025-49184HIGH7.5same product

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorizati...