CVE-2026-31382
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.
MEDIUM · CVSS 6.1
EPSS 0.00017
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0