Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.

This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1.
Published: 2026-07-01
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in DivvyDrive arises from insufficient neutralization of user input during web page generation, allowing malicious scripts to be stored in the application’s data store (C compromised field is rendered in a browser, the injected script executes with the privileges of the user viewing the page or other sensitive information.

Affected Systems

Affected are versions of DivvyDrive before 4.8.3.1, including the 4.8.2.23 build and all earlier releases from the same vendor.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in KEV catalog. The attack vector is inferred to require an actor who can submit or modify content that is stored by the application; after the malicious payload is persisted, it will run in the browsers of any users who later view the affected content.

Generated by OpenCVE AI on July 21, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to DivvyDrive 4.8.3.1 or later to eliminate the stored XSS flaw.
  • Implement proper output escaping or input validation on all fields that are rendered within web pages to prevent script injection.
  • Deploy a web application firewall or equivalent controls to detect and block suspicious script payloads submitted to the application.

Generated by OpenCVE AI on July 21, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Divvydrive
Divvydrive divvydrive
Vendors & Products Divvydrive
Divvydrive divvydrive

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.23 before v.4.8.3.1.
Title Stored XSS in DivvyDrive Information Technologies' DivvyDrive
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Divvydrive Divvydrive
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-01T14:55:07.615Z

Reserved: 2026-03-31T11:56:09.964Z

Link: CVE-2026-5220

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:03.505Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')