CVE-2026-12621: Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTime™ 3000 GNSS Time Server
Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GridTime 3000 GNSS Time Serverto a version that resolves this vulnerability.Fixed in 1.2r0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12621?
The severity of CVE-2026-12621 is medium, rated at 5.3 on the CVSS scale.
How do I fix CVE-2026-12621?
To fix CVE-2026-12621, update your GridTime 3000 GNSS Time Server to version 1.2r0.0 or later.
What type of vulnerability is CVE-2026-12621?
CVE-2026-12621 is a Cross-Site Scripting (XSS) vulnerability related to improper input handling in a password reset form.
Which versions of GridTime 3000 are affected by CVE-2026-12621?
CVE-2026-12621 affects GridTime 3000 versions from 1.0r0.03 before 1.2r0.0.
What impact does CVE-2026-12621 have on users?
CVE-2026-12621 can allow an attacker to execute malicious scripts in the context of users accessing the password reset form.