PT-2026-58030 · Unknown · Sustainable Irrigation Platform
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description
A stored cross-site scripting issue exists where unauthenticated attackers can inject arbitrary JavaScript by providing malicious payloads within program names submitted via HTTP requests. The flaw occurs because the application fails to perform output encoding on rendered program names, allowing the script to execute in the browsers of users who view the affected page. This is further facilitated if a passphrase is not required or if the default passphrase
opendoor is used.Recommendations
Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later.
Change the default passphrase
opendoor to a strong, unique passphrase.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sustainable Irrigation Platform