PT-2026-98846 · Unknown · Ail Framework

·

CVE-2026-100174

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AIL Framework (affected versions not specified)
Description The tag selector component located at var/www/static/js/tags.js is susceptible to stored cross-site scripting (XSS). An authenticated user with permissions to create custom tags can embed HTML payloads containing JavaScript event handlers within a tag name. The issue occurs because the renderComboItems function and the selected-tag rendering logic pass the displayField value directly to the jQuery html property, which inserts the string as raw HTML into the Document Object Model (DOM) instead of treating it as plain text. This allows arbitrary JavaScript execution in the browser of any authenticated user who views a page rendering the malicious tag, potentially leading to session hijacking, unauthorized data access, or form manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100174

Affected Products

Ail Framework