Sceawere

Vulnerability Detail

CVE-2026-39790UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated XSS in VikRentCar

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
e4jvikwp
Product
VikRentCar
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:51.777Z",
  "pubdate": "2026-10-06T09:17:51.777Z",
  "executiveSummary": "VikRentCar versions 1.4.6 and below contain a critical Unauthenticated Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper neutralization of user-supplied input before rendering it within the web application interface.\nThe vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript code within the context of a victim's browser session. By leveraging this, an attacker can hijack user sessions, manipulate the displayed content of the application, or perform unauthorized actions on behalf of legitimate users.\nBecause the vulnerability does not require authentication, the attack surface is significantly broadened, exposing the application to drive-by attacks. Successful exploitation compromises the integrity and confidentiality of the user's browser-side environment. Administrators of VikRentCar are advised to treat this as a high-risk security event, as it facilitates potential credential theft, session token interception, and the delivery of secondary malicious payloads, such as phishing redirects or malware distribution through the compromised portal.",
  "technicalDetails": "The vulnerability is classified as Reflected Cross-Site Scripting (XSS), originating from the application's failure to adequately sanitize or encode input parameters passed via HTTP GET or POST requests. Within the VikRentCar framework (versions 1.4.6 and below), specific entry points do not implement context-aware output encoding when reflecting user input back to the browser.\nRoot Cause Analysis: The core issue resides in the application's request handling logic, where user-controllable data is processed and subsequently embedded directly into the HTML response document without prior validation. When a malicious actor crafts a URL containing a crafted script payload within these vulnerable parameters, the server includes this payload in the generated response.\nAttack Flow: 1. The attacker identifies a target URL within the VikRentCar application that accepts parameters without strict filtering. 2. The attacker constructs a malicious payload, typically wrapping JavaScript within <script> tags or utilizing event handlers (e.g., onload, onerror). 3. The attacker social-engineers a victim into clicking the crafted URL. 4. Upon the victim's browser rendering the page, the server-side response reflects the payload. 5. The victim's browser interprets the injected string as executable script rather than plain text, resulting in immediate execution of the attacker's code.\nExploitation Context: Since the vulnerability is unauthenticated, no prior sessions or administrative credentials are required. The exploit is performed over standard web protocols (HTTP/HTTPS) and leverages the trust the victim has in the vulnerable domain. The injected JavaScript operates under the security context of the origin, granting it access to document objects, cookies (if not protected by HttpOnly flags), and local storage.\nPost-Exploitation Impact: Once the script executes, the attacker may capture sensitive information, modify the DOM to present fraudulent forms, or redirect the victim to an attacker-controlled domain. Given the nature of a rent-a-car application, this could lead to the theft of personal identifiable information (PII) or payment-related data if such fields are rendered during the session. The persistence of the attack is limited to the duration of the victim's session unless the script is designed to exploit other browser-based vulnerabilities or exfiltrate session data for permanent account hijacking."
}
CVE-2026-39790: Unauthenticated XSS in VikRentCar (HIGH Severity, CVSS: 7.1) | Sceawere