top of page
perceptive_background_267k.jpg

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authentica…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 17:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Database & Storage, Identity & Access

A reflected cross-site scripting (XSS) vulnerability has been identified in the Query Console component of Progress MarkLogic Server. The flaw affects versions prior to 11.3.6 and 12.0.3. A remote attacker can exploit this vulnerability by luring an authenticated administrator to visit a specially crafted URL. Upon successful exploitation, the attacker can execute arbitrary JavaScript within the administrator's browser session. This allows for credential capture and the ability to perform privileged administrative actions on behalf of the victim. The attack requires social engineering to trick the administrator into clicking a malicious link. Progress has issued a security bulletin classifying this as a critical security alert. Users are advised to upgrade to the patched versions 11.3.6 or 12.0.3 immediately.

Technical details

Mitigation steps:

Affected products:

Progress MarkLogic Server 11.x before 11.3.6
Progress MarkLogic Server 12.x before 12.0.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page