CVE-2025-15372 | youlaitech vue3-element-admin up to 3.4.0 Notice index.vue cross site scripting
A vulnerability classified as problematic has been found in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the component Notice Handler. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-15372. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way. If you want to get best quality of vulnerability data, you may have to visit VulDB.