PT-2026-68810 · Unknown · Project Ai
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIL Project (affected versions not specified)
Description
A stored cross-site scripting issue exists in the translation controls for chat messages and forum posts. The system inserts message and post identifiers directly into inline JavaScript
onclick handlers within the functions translateMessageToPreferredLanguage() and translatePostToPreferredLanguage(). While these values are HTML-template escaped, they are not safely encoded for use as JavaScript string literals inside an HTML attribute. An attacker can use a specially crafted identifier containing quotation marks or escape characters to terminate the string argument and inject arbitrary JavaScript. Since these values are stored, the malicious code executes in the victim's browser under the security origin of the AIL instance when they click the Translate to preferred language button.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Project Ai