Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.

This issue affects Q-smart NexT Poll: before 1.8.7.
Published: 2026-07-20
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the web page output of Bifra Engineering Consulting Ltd.'s Q‑smart NexT Poll application. When users submit data that is not properly neutralised, the data is saved and later rendered to other users, enabling the execution of arbitrary scripts in the victim’s browser. This can lead to credential theft, session hijacking, defacement, or the delivery of additional malware. The weakness is classified as CWE‑79, a typical input‑validation issue.

Affected Systems

The flaw exists in Bifra Engineering Consulting Ltd.'s Q‑smart NexT Poll prior to version 1.8.7. It affects any deployment of that product regardless of the host environment, as the vulnerability is triggered by user‑supplied input fields in the poll creation or response interfaces. No other vendors or product versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity with a medium likelihood of exploitation under the conditions described. EPSS score is 0.00162 (< 1%), reflecting a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, implying no known large‑scale exploitation. The most likely attack vector is via a legitimate user interface where the attacker supplies malicious payloads that are stored. Successful exploitation requires that the attacker can submit data to the application, but no elevated privileges are required. Consequently, all users who can view the poll outputs are at risk.

Generated by OpenCVE AI on July 30, 2026 at 19:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 1.8.7 or later, which eliminates the stored cross‑site scripting vulnerability.
  • Enforce strict input validation and output encoding for all user‑supplied fields to neutralise any malicious scripts.
  • Deploy a robust Content Security Policy that restricts executable scripts to trusted origins to block any arbitrary JavaScript execution.

Generated by OpenCVE AI on July 30, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Bifra Engineering Consulting
Bifra Engineering Consulting q-smart Next Poll
Vendors & Products Bifra Engineering Consulting
Bifra Engineering Consulting q-smart Next Poll

Mon, 20 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7.
Title Stored XSS in Bifra Engineering's Q-smart NexT Poll
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Bifra Engineering Consulting Q-smart Next Poll
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-20T18:22:48.613Z

Reserved: 2026-04-21T13:55:23.785Z

Link: CVE-2026-6793

cve-icon Vulnrichment

Updated: 2026-07-20T18:22:44.576Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')