Sceawere

Vulnerability Detail

CVE-2026-82969UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in eBA Plus

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
Bimser Solution Software Trade Inc.
Product
eBA Plus Document and Workflow Management System
Attack Type
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-28T09:17:07.267Z",
  "pubdate": "2026-09-28T09:17:07.267Z",
  "executiveSummary": "The eBA Plus Document and Workflow Management System is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, classified under CWE-79 (Improper Neutralization of Input During Web Page Generation).\nThis vulnerability exists due to insufficient input validation and output encoding of user-supplied data, allowing an attacker to inject and persist malicious scripts within the application.\nThe flaw affects versions ranging from 6.7.141 up to, but not including, 10.0.11.\nSuccessful exploitation enables an attacker to execute arbitrary JavaScript in the context of an unsuspecting user's browser session. This can lead to unauthorized access to sensitive information, session hijacking, or the performance of actions on behalf of the victim.\nThe risk to the organization is significant, as it can compromise user confidentiality and integrity within the document and workflow management environment. Attackers require access to the application to inject the payload, which is then stored and served to other users viewing the affected content.",
  "technicalDetails": "The vulnerability originates from the application's failure to properly sanitize or neutralize user-provided input before storing it in the persistent database and rendering it back to users in web pages.\nThis is a classic Stored XSS scenario, where the malicious payload is permanently stored on the target server (e.g., in a document description, workflow comment, or form field) and subsequently served to any user—including administrators—who accesses the affected page.\nThe exploitation flow begins when an attacker injects a malicious script payload through an input field that fails to perform adequate input validation. The application accepts this input and stores it server-side. When a victim subsequently navigates to a part of the application that renders the stored content, the browser interprets the injected payload as legitimate application code.\nBecause the payload originates from a trusted source (the application's own database), it bypasses many client-side security assumptions. The script executes within the security context of the victim's session, granting it access to the Document Object Model (DOM), browser cookies, and session tokens.\nThe technical impact includes the potential for session hijacking (by stealing session cookies via document.cookie), performing unauthorized administrative actions, redirection to malicious external sites, or capturing sensitive data displayed on the page. Because the payload is persistent, a single successful injection can impact all users who view the compromised document or workflow component, leading to a potentially large-scale compromise of user accounts.\nThe vulnerability affects eBA Plus Document and Workflow Management System versions from 6.7.141 before 10.0.11. The root cause is the reliance on flawed input handling mechanisms that allow executable script tags or event handlers to be accepted and stored without strict filtering or context-aware encoding."
}
CVE-2026-82969: Stored XSS in eBA Plus (MEDIUM Severity, CVSS: 5.4) | Sceawere