Sceawere

Vulnerability Detail

CVE-2026-94158UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Gloria Admin Panel Reflected XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
bkninja
Product
Gloria Admin Panel
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:39.653Z",
  "pubdate": "2026-10-09T10:16:39.653Z",
  "executiveSummary": "The Gloria Admin Panel is affected by a Reflected Cross-Site Scripting (XSS) vulnerability, classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability exists due to the application's failure to properly sanitize user-supplied input before rendering it within the web page context.\nSuccessful exploitation allows an unauthenticated or authenticated attacker to inject arbitrary malicious scripts, such as JavaScript, into the victim's browser session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of the user, sensitive data exfiltration, and redirection to malicious external domains.\nThis issue affects all versions of Gloria Admin Panel from n/a through 1.3.\nThe risk implication is high, as it grants attackers the ability to compromise administrative or user accounts, potentially leading to a full platform compromise depending on the user's privilege level.",
  "technicalDetails": "The vulnerability is a classic Reflected Cross-Site Scripting (XSS) flaw, stemming from the application's inadequate handling of HTTP request parameters. When the Gloria Admin Panel processes incoming requests, it fails to perform necessary input validation or output encoding on parameters that are subsequently reflected back to the user in the HTTP response.\nThe root cause lies in the server-side logic dynamically generating HTML content based on unvalidated user input. Because the application does not implement context-aware output encoding, an attacker can supply a malicious payload—typically containing script tags or event handlers—within the request parameters.\nThe attack flow begins when an attacker crafts a malicious URL containing a payload designed to execute in the context of the user's browser. The attacker then lures a target, such as an administrator, into clicking this link. Upon clicking, the victim's browser sends a request to the Gloria Admin Panel, which includes the injected script. The server processes the request and embeds the payload directly into the HTML document returned to the victim's browser.\nOnce received, the victim's browser treats the injected payload as trusted code originating from the legitimate origin. The malicious script then executes within the security context of the victim's session. This allows for various post-exploitation activities, including accessing document.cookie to steal session tokens, reading sensitive information displayed on the page, or performing unauthorized administrative actions by making background requests as the authenticated user.\nThis vulnerability is present in versions of Gloria Admin Panel ranging from n/a through 1.3. It does not require specific elevated privileges to trigger, as the execution occurs client-side within the context of the user who clicks the malicious link. The vulnerability is accessible over the network, provided the application is reachable, and poses a significant risk to the integrity and confidentiality of user sessions."
}
CVE-2026-94158: Gloria Admin Panel Reflected XSS (HIGH Severity, CVSS: 7.1) | Sceawere