Description
Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Bacularis versions 1.0.0 through 6.5.0 contain a stored cross‑site scripting flaw in the client address field. Malicious script content supplied by an attacker that is persisted and subsequently displayed to users will be executed within their browser context, allowing the injection of arbitrary code into the page rendering the stored data.

Affected Systems

Bacularis 1.0.0 to 6.5.0 are affected; no additional vendor or product information is provided in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, placing it in the medium severity range, and its EPSS score is listed as less than 1 %, indicating a low likelihood of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a user‑controlled input field: an attacker who can supply or modify the client address field can embed arbitrary JavaScript, which will execute whenever the data is rendered in a browser.

Generated by OpenCVE AI on September 21, 2026 at 19:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bacularis to the latest version that eliminates the flaw, if an up‑to‑date release exists.
  • Validate and sanitize all input for the client address field on the server side, stripping or properly escaping any HTML or script tags before storage.
  • Implement a strict content‑security‑policy header that disallows inline scripts or restricts script sources to trusted domains, limiting the impact of any residual stored scripts.

Generated by OpenCVE AI on September 21, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting in Bacularis Client Address Field

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting in Bacularis Client Address Field
Weaknesses CWE-79

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Stored XSS Vulnerability in Bacularis Client Address Field
Weaknesses CWE-79

Wed, 16 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Stored XSS Vulnerability in Bacularis Client Address Field
Weaknesses CWE-79

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-21T16:16:43.321Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88742

cve-icon Vulnrichment

Updated: 2026-09-21T16:16:25.288Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:19:19.563

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-88742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T20:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')