← Vulnerability feed

Vulnerability record · CVE-2025-49191 · published 12 June 2025

CVE-2025-49191: Sick field analytics clickjacking vulnerability

Sick · Field Analytics

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.

6.1 CVSS 3.1 Medium EPSS 0.35% · top 74.3% CWE-1021 · Clickjacking
6.1CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to create new dashboards or iFrame widgets.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49191 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-49199Sick field analytics insufficient verification of data authenticity vulnerabilityThe backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. Th…EPSS 0.33%9.1CVE-2025-49196Sick field analytics broken cryptographic algorithm vulnerabilityA service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive information, modify data in unexpected…EPSS 0.26%7.5CVE-2025-49200Sick field analytics information exposure vulnerabilityThe created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the …EPSS 0.46%7.5CVE-2025-49188Sick field analytics vulnerabilityThe application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.EPSS 0.44%7.5CVE-2025-49184Sick baggage analytics information exposure vulnerabilityA remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the pro…EPSS 0.49%6.5CVE-2025-49186Avaya media server improper restriction of authentication attempts vulnerabilityThe product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptibl…EPSS 0.37%6.1CVE-2025-49192Sick field analytics clickjacking vulnerabilityThe web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into cli…EPSS 0.33%6.1CVE-2025-49193Sick baggage analytics vulnerabilityThe application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., p…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2025-49191), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.