CVE-2026-104807
Received Received - Intake

Stored XSS in DigitalCanion Web Portal Configuration

Vulnerability report for CVE-2026-104807, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Switzerland Government Common Vulnerability Program

Description

DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration β†’ Domains, specifically in the β€œDescription” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in a web application. An authenticated attacker can inject malicious JavaScript or HTML into the Description field under Configuration β†’ Domains. The application does not properly validate or sanitize this input, allowing the malicious code to persist and execute when other users view the page.

Detection Guidance

To detect this stored XSS vulnerability, inspect the web portal's Configuration β†’ Domains section, specifically the Description field for any injected JavaScript or HTML content. Check the page source or browser developer tools for suspicious scripts in the rendered page.

Impact Analysis

If you are a user of the affected application, an attacker could alter the page's appearance, display fake content, or create phishing scenarios within the app's trusted interface. This could trick you into revealing sensitive information or performing unintended actions.

Mitigation Strategies

Immediately sanitize all user inputs in the Description field by implementing strict input validation and output encoding. Remove any existing malicious scripts from the Description field and restrict user permissions to prevent unauthorized modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104807. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart