Description
kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.
Published: 2026-09-16
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Network administrators should be aware that kkFileView versions 5.0.0 through 5.0.2 are vulnerable to a reflected cross‑site scripting flaw. The OnlinePreviewController forwards user‑supplied "page" and "kkagent" query parameters straight to FreeMarker templates without any sanitization, and the templates embed those values directly into raw JavaScript contexts. This omission allows an attacker to inject arbitrary client‑side code, leading to the execution of malicious scripts in the context of anyone who visits the crafted URL. The weakness corresponds to CWE‑79, which represents improper neutralization of input during web‑page generation.

Affected Systems

The affected product is kkFileView, a file‑viewer component used in internal web portals. Any deployment running versions 5.0.0, 5.0.1, or 5.0.2 with the /onlinePreview endpoint enabled is susceptible. No specific vendor or further product line is mentioned; it is inferred that the issue likely exists system‑wide for those versions.

Risk and Exploitability

The CVSS score is 6.1, indicating moderate severity. The nominal EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalogue, suggesting that active exploitation is currently unlikely. Nevertheless, the flaw can be exploited manually by placing a malicious payload in the 'page' or 'kkagent' parameters of a URL (e.g., /onlinePreview?page=...&kkagent=...). Based on the description, it is inferred that the likely attack vector involves embedding malicious payloads into these parameters to trigger script execution. Because the payload is reflected back into a JavaScript context, any user who loads the URL will have the script executed in their browser. Attacks could range from cookie theft to session hijacking or more complex phishing interactions, with impact confined to the victim’s session but potentially affecting sensitive data accessed through kkFileView.

Generated by OpenCVE AI on September 22, 2026 at 18:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the newest kkFileView release that addresses the XSS vulnerability.
  • Restrict access to the /onlinePreview endpoint to authenticated or trusted users only, limiting the attack surface.
  • Validate or encode the 'page' and 'kkagent' parameters before they are rendered by the FreeMarker templates, preventing script injection into JavaScript contexts.

Generated by OpenCVE AI on September 22, 2026 at 18:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Reflected XSS Vulnerability via /onlinePreview in kkFileView

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Reflected XSS Vulnerability via /onlinePreview in kkFileView
Weaknesses CWE-79

Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:17:34.592Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88593

cve-icon Vulnrichment

Updated: 2026-09-22T15:16:46.842Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:18.913

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-88593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')