Cross Site Scripting Vulnerability in Governikus AusweisApp by Governikus
CVE-2026-90848
5.3MEDIUM
What is CVE-2026-90848?
A security flaw has been detected in the Governikus AusweisApp, specifically in the StartPAOSResponse Handler component. This vulnerability allows for cross site scripting (XSS) by manipulating the ResultMessage argument, potentially enabling remote attackers to execute harmful scripts in the context of the user's session. Users are strongly advised to upgrade to version 2.5.5 to remediate this issue and enhance security against such attacks.
Affected Version(s)
AusweisApp 2.5.0
AusweisApp 2.5.1
AusweisApp 2.5.2
