CVE-2026-44667

🟡 Monitoruj

Przechowywane XSS w FACTION umożliwia wykonanie złośliwego kodu w przeglądarkach użytkowników.

CVSS
8.7
EPSS
0.0%
Exploit
none
Vendor
Opis źródłowy (NVD)

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification file preview flows. User-supplied filename values are persisted and then rendered into HTML and attribute contexts without output encoding, allowing attacker-controlled JavaScript to execute in the browser of any user who opens the affected verification/remediation views. Because the payload is stored server-side and rendered to other users, exploitation is persistent and can impact privileged accounts. This vulnerability is fixed in 1.8.3.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.0%
Opublikowano (NVD)2026-05-26 18:16:50 UTC
Ostatnia modyfikacja (NVD)2026-05-27 17:16:39 UTC
Referencje