Sceawere

Vulnerability Detail

CVE-2026-108566UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

InstantSoft icms2 XSS Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
3h ago
Vendor
InstantSoft
Product
icms2
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in InstantSoft icms2 up to 2.18.2. This issue affects the function index of the file templates/default/controllers/messages/index.tpl.php of the component Private Message Handler. Such manipulation of the argument nickname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 3a1ec8fcb073a46d06a2ab83bc2bf68225834281. It is best practice to apply a patch to resolve this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-10-11T10:16:38.727Z",
  "pubdate": "2026-10-11T10:16:38.727Z",
  "executiveSummary": "A cross-site scripting (XSS) vulnerability exists in the Private Message Handler component of InstantSoft icms2, specifically within versions up to 2.18.2.\nThe vulnerability resides in the processing of the 'nickname' argument within the 'index' function of 'templates/default/controllers/messages/index.tpl.php'.\nThis flaw permits remote attackers to inject and execute arbitrary JavaScript code within the context of a victim's session, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive session tokens.\nThe vulnerability is publicly disclosed, increasing the risk of exploitation by malicious actors.\nSuccessful exploitation requires no specialized privileges, as the attack vector is exposed via network-accessible parameters.\nImmediate application of the vendor-provided patch is recommended to mitigate risk.",
  "technicalDetails": "The root cause of this vulnerability is the improper neutralization of user-supplied input within the 'nickname' parameter before it is reflected in the web application's interface.\nSpecifically, the 'index' function within 'templates/default/controllers/messages/index.tpl.php' fails to adequately sanitize or encode the 'nickname' variable. This lack of output encoding allows the browser to interpret malicious input as executable script rather than plain text.\nThe attack flow begins when a remote, unauthenticated or authenticated attacker crafts a malicious URL containing a payload designed to break out of the HTML context. For instance, an attacker may append a payload such as <script>alert(document.cookie)</script> to the 'nickname' parameter.\nWhen a legitimate user or administrator clicks the crafted link, the server processes the 'nickname' input and embeds the unsanitized payload directly into the response rendered by 'index.tpl.php'.\nUpon receipt of the HTTP response, the victim's browser executes the injected JavaScript code in the context of the icms2 origin. This violates the security boundary established by the Same-Origin Policy (SOP).\nThe impact of this XSS vulnerability is significant. Once the attacker achieves arbitrary code execution in the victim's browser, they can perform actions on behalf of the victim, such as modifying account settings, accessing private messages, or capturing sensitive session identifiers. If the victim is an administrative user, the impact could result in a full site compromise.\nThe vulnerability affects all versions of InstantSoft icms2 up to and including 2.18.2. The specific component responsible is the Private Message Handler, which does not enforce strict input validation or contextual output encoding for user-supplied data in the messaging module.\nThe availability of public exploit code lowers the barrier to entry, enabling attackers to conduct automated or targeted attacks against vulnerable icms2 installations without significant technical effort."
}
CVE-2026-108566: InstantSoft icms2 XSS Vulnerability (LOW Severity, CVSS: 3.5) | Sceawere