CVE-2026-82969
Received Received - Intake

Stored XSS in Bimser eBA Plus Document Management System

Vulnerability report for CVE-2026-82969, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Stored XSS. This issue affects eBA Plus Document and Workflow Management System: from 6.7.141 before 10.0.11.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bimser_solution_software_trade_inc eba_plus_document_and_workflow_management_system From 6.7.141 (inc) to 10.0.11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Bimser Solution Software Trade Inc.'s EBA Plus Document and Workflow Management System. It allows attackers to inject malicious scripts into web pages that are then stored and served to other users, potentially executing unauthorized actions in their browsers.

Detection Guidance

This vulnerability is a stored XSS issue in Bimser eBA Plus Document and Workflow Management System versions before 10.0.11. Detection typically requires manual testing of input fields in the application for XSS payloads. Use tools like Burp Suite or OWASP ZAP to intercept and test inputs. Check for reflected or stored XSS by injecting basic payloads such as <script>alert(1)</script> in form fields, URLs, or other user-input areas.

Impact Analysis

If you use the affected EBA Plus system, attackers could steal session cookies, redirect you to malicious sites, or perform actions on your behalf without your knowledge. This could lead to data theft, unauthorized access, or account compromise.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data or HIPAA by compromising protected health information if the system handles such data. It may lead to non-compliance due to inadequate protection against cross-site scripting attacks.

Mitigation Strategies

Update the eBA Plus Document and Workflow Management System to version 10.0.11 or later to address the stored XSS vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82969. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart