Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS.

This issue affects Bar Association Website: through 18092026. 
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client-side code execution via reflected XSS
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises from improper neutralization of user-supplied input during web page generation, enabling attackers to inject malicious scripts that execute in the victim’s browser. This reflected XSS can lead to session hijacking, credential theft, or the execution of arbitrary JavaScript within the user’s environment, as identified by CWE-79. The impact is confined to the client side but can compromise sensitive data and user trust.

Affected Systems

KA Informatics Technologies Ltd. Co. operates the Bar Association Website, which is vulnerable through all releases up to 18092026. The vendor has been notified of the disclosure but has yet to respond or publish a fix, leaving the public‑facing application exposed.

Risk and Exploitability

The CVSS score of 6.1 classifies this flaw as moderate, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a crafted URL or input field that echoes a user‑provided value back to the page, allowing an attacker to embed JavaScript that runs in the context of any user who visits the page.

Generated by OpenCVE AI on September 19, 2026 at 20:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Escape or encode all reflected user input on the server side using a trusted library or framework
  • Add a strict Content Security Policy header that limits trusted script sources to a known safe domain
  • Conduct regular security scans (e.g., OWASP ZAP or manual testing) to detect and remediate XSS vectors

Generated by OpenCVE AI on September 19, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Ka Informatics Technologies
Ka Informatics Technologies bar Association Website
Vendors & Products Ka Informatics Technologies
Ka Informatics Technologies bar Association Website

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through 18092026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Reflected XSS in KA Informatics' Bar Association Website
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ka Informatics Technologies Bar Association Website
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-18T19:14:52.173Z

Reserved: 2026-06-09T07:22:02.508Z

Link: CVE-2026-11757

cve-icon Vulnrichment

Updated: 2026-09-18T19:14:48.444Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:57.710

Modified: 2026-09-18T20:17:04.200

Link: CVE-2026-11757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:58Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')