Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS.

This issue affects Access Control System (GKS): before Version 2.
Published: 2026-07-07
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation creates a Stored Cross‑Site Scripting flaw. The weakness, identified as CWE‑79, allows an attacker to embed malicious scripts that are later executed in other users’ browsers when the stored data is viewed. This can lead to execution of arbitrary JavaScript in the victim’s browser, potentially exposing sensitive information or performing unauthorized actions. The specific outcomes depend on the stored context and victim interaction, but any execution in a user's browser could compromise their session or data.

Affected Systems

Armiya Information Technologies Ltd. Co. Access Control System (GKS) versions prior to 2 are affected.

Risk and Exploitability

The CVSS score of 6.1 indicates medium severity, while the EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves web input fields that accept and store arbitrary data for later display without proper encoding, enabling an attacker to inject a payload via the application’s input controls that is executed in the browsers of other users who view the stored content.

Generated by OpenCVE AI on July 26, 2026 at 19:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Access Control System (GKS) to version 2 or later to eliminate the stored XSS weakness.
  • Implement server‑side input validation and output encoding on all forms that store data for later rendering to prevent future injection attacks.
  • Deploy a Content‑Security‑Policy header that disallows inline script execution to reduce the impact of any remaining XSS vectors.

Generated by OpenCVE AI on July 26, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Armiya
Armiya access Control System (gks)
Vendors & Products Armiya
Armiya access Control System (gks)

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2.
Title Stored XSS in Armiya Technologies' Access Control System
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Armiya Access Control System (gks)
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:27:35.094Z

Reserved: 2026-05-11T12:00:31.251Z

Link: CVE-2026-8306

cve-icon Vulnrichment

Updated: 2026-07-07T13:27:28.757Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')