Sceawere

Vulnerability Detail

CVE-2026-102292UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MateisHomePage XSS via Search

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
coolbeans1212
Product
MateisHomePage-Website
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation of the argument Search causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 6406308df9771d2fd477b56dafe4878dd846df6e. Applying a patch is the recommended action to fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T06:16:58.320Z",
  "pubdate": "2026-09-29T06:16:58.320Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the 'users.php' file of the coolbeans1212 MateisHomePage-Website.\nThe vulnerability originates from improper neutralization of user-supplied input provided to the 'Search' argument, which is then rendered in the browser without adequate sanitization.\nThis flaw allows remote attackers to execute arbitrary JavaScript in the context of the victim's session, potentially leading to unauthorized actions, session hijacking, or sensitive data exfiltration.\nThe product utilizes a rolling release model, meaning specific versioning is unavailable; however, the vulnerability affects all iterations up to commit ea2a4226deeca27ab1fb9df0552ec76444547811.\nThe risk is considered significant as an exploit has been publicly released, lowering the barrier to entry for potential adversaries.\nSuccessful exploitation does not explicitly require prior authentication, and the attack can be initiated remotely, necessitating immediate patching.",
  "technicalDetails": "The vulnerability is identified as a Reflected Cross-Site Scripting (XSS) flaw located within the 'users.php' component of the MateisHomePage-Website application. The root cause is the failure of the application to properly sanitize or encode the 'Search' query parameter before embedding it into the HTML document structure of the response.\nWhen a user submits a search query, the application dynamically generates a response containing the user-provided input. Because this input is not validated against a whitelist of characters nor passed through an appropriate output encoding function (such as htmlspecialchars in PHP), an attacker can inject malicious JavaScript payloads. The browser, unable to distinguish between legitimate content and the injected script, executes the payload within the security context of the victim's session.\nThe attack flow proceeds as follows: 1) The attacker constructs a crafted URL containing a payload within the 'Search' argument of 'users.php'. 2) The attacker lures a victim to navigate to this URL via social engineering or embedded links. 3) The web server receives the request and reflects the malicious script back to the user's browser. 4) The victim's browser processes the response and executes the injected script.\nThis vulnerability is classified as remotely exploitable, requiring no specific privileges or authentication to trigger if the vulnerable page is publicly accessible. The impact of the successful execution of this payload includes, but is not limited to: access to browser-stored cookies and session tokens, redirection to malicious third-party websites, defacement of the rendered web page, and the ability to perform actions on behalf of the user within the web application interface.\nThe scope of the affected versions encompasses all deployments of the coolbeans1212 MateisHomePage-Website repository up to commit ea2a4226deeca27ab1fb9df0552ec76444547811. Given the continuous delivery model, standard version tracking is not applicable, emphasizing the reliance on the provided patch identifier 6406308df9771d2fd477b56dafe4878dd846df6e as the primary indicator for remediation.\nPost-exploitation, an adversary could achieve persistent access or elevated impact if the application uses sensitive cookies without the HttpOnly attribute, facilitating session hijacking."
}
CVE-2026-102292: MateisHomePage XSS via Search (MEDIUM Severity, CVSS: 4.3) | Sceawere