CVE-2026-90848 | Governikus AusweisApp up to 2.5.4 StartPAOSResponse ResultMessage cross site scripting
A vulnerability was found in Governikus AusweisApp up to 2.5.4. It has been declared as problematic. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-90848. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
This CVE was requested by the vendor.VulDB Recent EntriesRead More