Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a stored cross‑site scripting vulnerability in Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources. When a malicious script is submitted through an allowed input field, it is persistently stored and later rendered as part of a web page for any user who views that content. The defect is classified as CWE‑79 and carries a CVSS score of 5.4, indicating a medium‑severity risk.

Affected Systems

Bilin Software and Informatics Consultancy Inc.’s HUMANIST Digital Human Resources, versions prior to 26.1, including 26.0, are affected. Any installation of the product that has not been upgraded to the 26.1 release or newer remains vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the attacker would need to submit malicious input through an input field that is later rendered into a web page. The likely attack vector is the web interface, but this is not stated directly in the CVE data. The exploit requires another user to view the resulting content after the payload is stored. The CVSS score of 5.4 indicates a medium severity, and the EPSS score is <1% with no listing in KEV, suggesting limited public exploitation.

Generated by OpenCVE AI on August 4, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 26.1 or later, which contains the fix for the stored XSS issue.
  • Apply proper output encoding or escaping to all user‑generated content so that scripts cannot be executed in browsers.
  • Limit content creation privileges to trusted administrators until the update is applied, reducing the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title Stored XSS in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:07:00.725Z

Reserved: 2026-06-30T08:32:42.695Z

Link: CVE-2026-14192

cve-icon Vulnrichment

Updated: 2026-08-04T13:06:42.457Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:31.810

Modified: 2026-08-04T13:17:35.527

Link: CVE-2026-14192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:00Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')