Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.

This issue affects Enocta Platform: through 2026-09-28.
Published: 2026-09-28
Score: 4.1 Medium
EPSS: n/a
KEV: No
Impact: Cross-site scripting
Action: Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of user‑supplied input in web page generation, allowing cross‑site scripting through HTML attribute injection. This weakness can let an attacker embed malicious scripts or modify page content. It is a type of XSS flaw classified as CWE‑79.

Affected Systems

The affected product is Enocta Educational Technologies Inc.’s Enocta Platform, all releases up to 2026‑09‑28. No specific sub‑components are identified, and the vendor does not list separate version numbers for the affected modules.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate impact, and the absence of an EPSS score leaves the exact likelihood uncertain. Because the flaw arises from un‑sanitized input, an attacker could exploit it by crafting a malicious payload in a URL or form field accessible to end‑users. No entry in the CISA KEV catalog suggests public exploitation is not yet documented, but the web‑based nature of the flaw warrants prompt attention.

Generated by OpenCVE AI on September 28, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest Enocta Platform patch that addresses the XSS vulnerability.
  • Enforce strict input validation and output encoding for all HTML attributes to prevent injection of malicious content.
  • Deploy a Content Security Policy (CSP) header to restrict the execution of scripts and mitigate the effects of any remaining XSS vectors.

Generated by OpenCVE AI on September 28, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue affects Enocta Platform: through 2026-09-28.
Title HTML Injection in Enocta Educational's Enocta Platform
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-28T13:31:27.844Z

Reserved: 2026-08-28T13:58:06.081Z

Link: CVE-2026-82326

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:03.595Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:23.113

Modified: 2026-09-28T14:31:05.267

Link: CVE-2026-82326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')