Sceawere

Vulnerability Detail

CVE-2026-93951UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zeinet Reflected XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
2h ago
Vendor
Bracketweb
Product
Zeinet
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Zeinet zeinet allows Reflected XSS.This issue affects Zeinet: from n/a through 1.0.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-10T08:17:07.437Z",
  "pubdate": "2026-10-10T08:17:07.437Z",
  "executiveSummary": "The Bracketweb Zeinet application is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability, classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability allows unauthenticated remote attackers to inject malicious client-side scripts into web pages rendered by the application.\nThe issue affects all Zeinet versions from n/a through 1.0.0.\nSuccessful exploitation permits the execution of arbitrary JavaScript within the context of the victim's browser session, leading to potential session hijacking, unauthorized actions performed on behalf of the user, or the redirection of victims to malicious domains.\nThe primary risk stems from the lack of adequate input sanitization and output encoding for user-supplied data transmitted via HTTP requests.\nAttackers can leverage this flaw by delivering crafted links to users, which, when accessed, execute the embedded script without requiring elevated privileges.",
  "technicalDetails": "The root cause of the vulnerability is the application's failure to properly neutralize user-controllable input before reflecting it back to the client in the HTTP response. The Zeinet application processes input parameters and injects them directly into the Document Object Model (DOM) or HTML response body without implementing context-aware output encoding.\nThe attack flow commences when an attacker identifies an entry point where user input is reflected in the server response. The attacker crafts a malicious URL containing a payload—typically a script tag or an HTML attribute containing JavaScript execution primitives (e.g., onerror, onload).\nUpon a victim navigating to the malicious URL, the Zeinet server includes the unvalidated script payload in the resulting web page. The victim's web browser, failing to distinguish between legitimate content and the injected script, executes the malicious code within the security context of the origin associated with Zeinet.\nBecause the payload executes in the victim's session context, it inherits the application's cookies, session tokens, and permissions. This enables the attacker to conduct actions such as extracting sensitive information from the page, modifying the DOM to facilitate phishing, or exfiltrating browser-stored credentials to an external listener controlled by the attacker.\nThis vulnerability is classified as Reflected XSS because the payload is not stored persistently on the server but is instead returned immediately to the client in the response to the initial malicious request. There are no authentication or privilege requirements for this exploit, as the attack is directed at the client-side session. The exploit is accessible over standard network vectors and relies on social engineering to entice the victim into clicking the crafted link. The lack of Content Security Policy (CSP) headers or input validation mechanisms exacerbates the risk, allowing virtually unrestricted script injection within the vulnerable response stream."
}
CVE-2026-93951: Zeinet Reflected XSS Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere