Sceawere
Vulnerability Detail
CVE-2026-87752UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Agentis XSS via HTML Attributes
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 4h ago
- Vendor
- Rolantis Information Technologies Tourism Industry…
- Product
- Agentis
- Attack Type
- CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-09-28T12:17:41.093Z",
"pubdate": "2026-09-28T12:17:41.093Z",
"executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists within the Rolantis Information Technologies Agentis platform, specifically affecting versions 4.44 through 4.6.\nThe vulnerability arises from improper neutralization of user-supplied input during the generation of web pages, allowing for the injection of malicious scripts into HTML attributes.\nSuccessful exploitation permits an attacker to execute arbitrary JavaScript within the context of a victim's browser session.\nThe impact includes unauthorized access to sensitive user data, session hijacking, defacement of web content, and potential redirection to malicious external domains.\nExploitation requires that an attacker successfully influences input fields processed by the application, which are then improperly rendered within HTML attribute contexts.\nThis vulnerability poses a significant risk to application integrity and user privacy, necessitating immediate attention to input validation and output encoding mechanisms.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Agentis application to implement robust output encoding or sanitization for input data rendered within HTML attributes. When the application dynamically generates web pages, it processes user-provided parameters that are subsequently embedded into attribute values without adequate filtering of special characters such as quotes, angle brackets, or parentheses.\nThe vulnerability specifically manifests as an Attribute-Based Cross-Site Scripting (XSS) flaw. In this scenario, an attacker can break out of an intended HTML attribute context—such as 'value', 'href', or 'src'—by injecting breaking characters like double-quotes (\") followed by malicious event handlers (e.g., 'onmouseover', 'onerror', or 'onload').\nThe attack flow proceeds as follows: First, the attacker identifies an input vector within the Agentis interface that is reflected back to the user within an HTML tag attribute. Second, the attacker crafts a payload designed to terminate the existing attribute and inject a JavaScript event handler. Third, the attacker lures or forces an authenticated or unauthenticated user to interact with the specially crafted URL or input field. Finally, when the user's browser renders the page, the injected payload executes with the privileges of the victim's session.\nBecause the payload executes within the Document Object Model (DOM) of the legitimate domain, the malicious script can bypass Same-Origin Policy (SOP) restrictions, allowing for the extraction of document cookies, session tokens, and localStorage contents. This enables the attacker to perform actions on behalf of the user or gain persistent unauthorized access.\nThe vulnerability affects Agentis versions from 4.44 before 4.6. The exploitation process is highly effective in scenarios where the application reflects input without verifying the structure of the resulting HTML tags. Because the payload is executed client-side, it operates independently of server-side logic once the injected code is rendered, making it a critical threat vector for persistent and reflected XSS attacks.\nThe lack of proper Context-Aware Encoding means that even if basic sanitization is applied, specific HTML attributes may remain susceptible if the filter does not account for JavaScript protocol handlers or attribute-context-specific termination characters."
}