Sceawere

Vulnerability Detail

CVE-2026-11747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in syWEB

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
2h ago
Vendor
Seres Software
Product
syWEB
Attack Type
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syWEB allows Reflected XSS. This issue affects syWEB: through 27082026. NOTE: The vendor was contacted and it was learned that the product is not supported.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-27T17:17:07.000Z",
  "pubdate": "2026-08-27T17:17:07.000Z",
  "executiveSummary": "The syWEB application, through version 27082026, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability stemming from improper neutralization of user-supplied input during the generation of web pages.\nThis vulnerability allows an unauthenticated attacker to inject malicious scripts into the web interface, which are subsequently executed within the context of a victim's browser session.\nSuccessful exploitation can lead to unauthorized actions performed on behalf of the victim, theft of session cookies, or the exfiltration of sensitive information.\nGiven that the vendor no longer supports syWEB, there is no official path for security patches, leaving deployed instances permanently exposed to this flaw.\nOrganizations relying on this product are at high risk, as attackers can weaponize this vulnerability via social engineering to execute arbitrary client-side code without elevated privileges.",
  "technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation. The root cause is the application's failure to adequately sanitize or encode user-provided input parameters before reflecting them back to the user within the HTTP response body.\nIn a typical attack flow, an attacker crafts a malicious URL containing a payload—such as a JavaScript snippet embedded within a query parameter—and distributes this link to an unsuspecting user via phishing or other social engineering tactics.\nWhen the authenticated or unauthenticated user clicks the link, the syWEB server receives the request, processes the malicious input, and reflects the unencoded payload directly into the rendered HTML content of the page.\nBecause the server fails to enforce context-aware output encoding (such as HTML entity encoding or attribute encoding), the victim's browser interprets the injected string as legitimate executable code rather than plain text.\nThe attack operates entirely client-side, executing within the security context (Domain/Origin) of the syWEB application. This grants the injected script access to the Document Object Model (DOM), local storage, and session-related cookies protected by insufficient security flags.\nPotential post-exploitation activities include the capture of sensitive user data, unauthorized modifications to the page content to deceive the user, or the redirection of the victim to attacker-controlled domains.\nSince the product is end-of-life and unsupported, exploitation requires no authentication or specific privilege level; the exposure is inherent to the application's design, making it accessible to anyone with network reach to the web server.\nThe vulnerability affects all versions of syWEB up to and including 27082026."
}
CVE-2026-11747: Reflected XSS in syWEB (MEDIUM Severity, CVSS: 6.1) - Sceawere