CyberRota Analysis
AI-GeneratedA vulnerability exists in the StartPAOSResponse Handler of Governikus AusweisApp versions up to 2.5.4, allowing for remote cross-site scripting (XSS) attacks through manipulation of the ResultMessage argument. Organizations using this application should prioritize upgrading to version 2.5.5 to mitigate potential exploitation risks. This issue is particularly relevant for entities handling sensitive user data, as it could lead to unauthorized access or data leakage.
Original NVD Description
A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address this issue. It is recommended to upgrade the affected component. This CVE was requested by the vendor.