Cross Site Scripting Vulnerability in TDuckApp tduck-platform
CVE-2026-90528
5.1MEDIUM
What is CVE-2026-90528?
A vulnerability exists in the TDuckApp tduck-platform, specifically in the Form Write View component located at tduck-front/src/views/form/write/index.vue. This flaw allows for remote manipulation of the argument submitShowCustomPageContent, which can lead to the execution of injected scripts in the context of the user's browser. Despite the vulnerability being reported, no response has been issued by the project maintainers, raising concerns about the security posture of the application.
Affected Version(s)
tduck-platform 5.0
tduck-platform 5.1
tduck-platform 5.2
