PT-2026-98853 · Unknown · Ail Framework
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
AIL Framework (affected versions not specified)
Description
The crawler splash domain page
showDomain.html is susceptible to stored cross-site script injection (XSS). This occurs because user-supplied data from imported crawler captures—specifically item IDs, URLs, and screenshot file paths—is interpolated directly into inline JavaScript contexts within the HTML template. The issue manifests in an onclick attribute that embeds raw screenshot and URL values into a JavaScript function call, as well as an inline script block that assigns a screenshot value to a JavaScript variable without proper escaping. An attacker with a user-role API client can import malicious crawler captures containing JavaScript payloads. When a user views the affected domain page, the script executes in their browser context, which may lead to session hijacking, data exfiltration, or unauthorized actions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ail Framework