Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting.

This issue affects DoXBASE: through 27082026. 
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-27
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting that can enable execution of arbitrary client‑side scripts, allowing session hijacking, defacement, or malicious redirection
Action: Assess Impact
AI Analysis

Impact

BilPark Informatics Technologies Industry and Trade Inc.’s DoXBASE contains an improper neutralization of input during web page generation, resulting in reflected cross‑site scripting. The flaw allows an attacker to inject malicious scripts that execute in the victim’s browser, potentially enabling session theft, defacement of the web interface, or the injection of additional malware through the user’s context.

Affected Systems

BilPark Informatics Technologies Industry and Trade Inc.’s DoXBASE, affected through and including version 27082026. No other affected versions are listed.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower but non‑negligible risk. The likely attack vector is client‑side: an attacker would craft a malicious URL or input that, when viewed or processed by a user of DoXBASE, leads to execution of injected scripts. Successful exploitation could compromise user sessions and expose sensitive data within the web application’s domain.

Generated by OpenCVE AI on August 27, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available patch or fix for DoXBASE once released by BilPark Informatics Technologies Industry and Trade Inc.
  • Implement a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted domains.
  • Enforce proper input validation and output encoding on all user‑supplied data to prevent reflected XSS.
  • Monitor web application logs for anomalous user agent strings or unexpected script injections.

Generated by OpenCVE AI on August 27, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilpark Informatics Technologies Industry And Trade
Bilpark Informatics Technologies Industry And Trade doxbase
Vendors & Products Bilpark Informatics Technologies Industry And Trade
Bilpark Informatics Technologies Industry And Trade doxbase

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Reflected XSS in BilPark's DoXBASE
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Bilpark Informatics Technologies Industry And Trade Doxbase
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-27T19:42:02.260Z

Reserved: 2026-04-07T13:37:28.745Z

Link: CVE-2026-5738

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-27T17:18:58.570

Modified: 2026-08-28T15:28:32.763

Link: CVE-2026-5738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:23:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')