Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.

This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.
Published: 2026-07-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that stems from improper neutralization of user input during page generation. This weakness is classified as CWE‑79. Because the application accepts and displays HTML content without adequate sanitization, an attacker can embed malicious scripts that execute in the browsers of any user who views the affected content. This client‑side code execution enables cookie theft, and other user‑level compromises. The description does not detail organization‑wide impact, but typical outcomes of stored XSS include compromise of user accounts and unauthorized data exfiltration.

Affected Systems

DivvyDrive Information Technologies Inc.'s product DivvyDrive is impacted from version 4.8.2.23 through, but not.8.3.1. All releases within that range require remediation. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 5.4 classifies the flaw as moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred to be remote through a web form or API that accepts user content user‑level compromise or credential theft.

Generated by OpenCVE AI on July 21, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DivvyDrive to version 4.8.3.1 or later to eliminate the stored‑XSS flaw.
  • Implement strict input sanitization or content‑escaping for all user‑controlled fields that are rendered in web pages to prevent injection of executable scripts.
  • Deploy a web application firewall or equivalent filtering layer to block or neutralize malicious scripts before they reach the browser.

Generated by OpenCVE AI on July 21, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Divvydrive
Divvydrive divvydrive
Vendors & Products Divvydrive
Divvydrive divvydrive

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from v.4.8.2.23 before v.4.8.3.1.
Title Stored XSS in DivvyDrive Information Technologies' DivvyDrive
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Divvydrive Divvydrive
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-01T14:54:14.126Z

Reserved: 2026-04-14T15:03:55.739Z

Link: CVE-2026-6283

cve-icon Vulnrichment

Updated: 2026-07-01T14:54:10.589Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')