Knowledge Base
Searching in : Trouble report
ID:TR09X11989
Added on: 2026-09-23
Last Update: 2026-10-06
Solved in version: 10.2.3, 9.10.1 and 8.28.1
Platform: All Platforms
Product: NoMachine Web Player
Severity: Serious
Status: Solved
Print this article

Cross-site scripting (XSS) vulnerability in web sessions may be exploited for code injection

A malicious user could exploit an XSS vulnerability in the displaying of error templates to inject arbitrary client-side code in the web page.

SOLVED, Released in version 10.2.3, 9.10.1 and 8.28.1