PT-2026-82502 · Flowintel · Flowintel
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
Stored Cross-Site Scripting (XSS) occurs because calendar event titles are rendered using
innerHTML. Since these titles are derived from case titles, a user with permissions to create or modify a case title can inject HTML or script-capable content. This content is subsequently executed by the browser when another user views the calendar. The issue involves the use of innerHTML to assign the arg.event.title variable.Recommendations
For versions 3.3.0 and later, update the software to replace the use of
innerHTML with textContent when rendering the arg.event.title variable and the static download icon.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flowintel