Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS.

This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Published: 2026-07-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, allowing stored cross‑site scripting to be inserted into pages served by TR7 Cyber Defense Inc. WAF‑ASP. This flaw is a CWE‑79 type input validation weakness that permits attackers to embed malicious JavaScript into content that is later rendered for other users.

Affected Systems

TR7 Cyber Defense Inc. WAF‑ASP is affected, starting with version v1.0.324.900 and including all versions up to but not including v1.4.0.117. Users who maintain these releases are vulnerable until they upgrade beyond v1.4.0.117 or apply an equivalent fix.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. BecauseAF‑ASP processes content to generate web likely attack vector is a remote or local injection of malicious script via a web interface that stores user data. Successful exploitation requires that the injected script be stored and subsequently rendered, allowing execution of client‑side code in the context of other users who access the page.

Generated by OpenCVE AI on July 21, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TR7 WAF‑ASP to.117 or later, which includes the patch for the stored XSS flaw.
  • If an upgrade cannot be performed immediately, restrict or sanitize any input that is stored for later page rendering, ensuring that all user‑supplied data is properly encoded or escaped before output.
  • Conduct a configuration review of the WAF to confirm that, and monitor event logs for signs of injection attempts or anomalous user‑agent activity.

Generated by OpenCVE AI on July 21, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
Title Stored XSS in TR7's WAF-ASP
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-02T13:15:20.596Z

Reserved: 2026-03-24T13:35:28.124Z

Link: CVE-2026-4772

cve-icon Vulnrichment

Updated: 2026-07-02T13:15:17.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')