CVE-2026-5015 | elecV2 elecV2P up to 3.8.3 Endpoint /logs filename cross site scripting (Issue 201)
A vulnerability was found in elecV2 elecV2P up to 3.8.3. It has been rated as problematic. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename causes cross site scripting.
The identification of this vulnerability is CVE-2026-5015. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.