CVE-2026-28280 | jmpsec osctrl up to 0.4.x Query Parameter cross site scripting (GHSA-4rv8-5cmm-2r22)
A vulnerability identified as problematic has been detected in jmpsec osctrl up to 0.4.x. This affects an unknown function of the component Query Parameter Handler. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-28280. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.