Description
A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Assess Impact
AI Analysis

Impact

This vulnerability resides in add_task.php, allowing an attacker to supply a crafted og_objects.name argument that the system outputs without adequate sanitization. The flaw enables the injection of arbitrary JavaScript code into the page context, granting an attacker the ability to steal session cookies, execute malicious actions on behalf of logged‑in users, or deface the application interface. The error does not provide direct code execution on the server, but the XSS payload can be delivered remotely and leveraged against any authenticated or unauthenticated user visiting the affected page.

Affected Systems

The issue affects the Feng Office product from Fengoffice. All releases of Feng Office up to version 3.11.13.11 are vulnerable. No official patch version is listed, so users should seek later releases or vendor‑issued fixes that address this flaw.

Risk and Exploitability

The CVSS score of 5.1 classifies the vulnerability as Medium severity. The EPSS score of < 1% indicates a low exploitation probability, and the flaw is not included in the CISA KEV catalog, suggesting that exploitation may not yet be widespread. However, the vulnerability is publicly disclosed, and the remote attack vector allows anyone to craft malicious input. Because the flaw relies on user‑controlled data being reflected unencoded, automated or targeted scripts can deliver attacks against any user visiting the affected page. System administrators should verify whether a newer release or patch is available and consider mitigating the vulnerability until a fix is applied.

Generated by OpenCVE AI on September 15, 2026 at 17:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade to a later version of Feng Office that addresses the cross‑site scripting flaw in the getTitle function.
  • If an immediate patch is unavailable, modify the add_task.php template or underlying rendering engine to properly escape or encode any user‑supplied og_objects.name values, thereby mitigating CWE-79.
  • Implement server‑side validation for og_objects.name to allow only expected alphanumeric content and reject any injection attempts, addressing both CWE-79 and potential CWE-94 (Code Injection) risks.

Generated by OpenCVE AI on September 15, 2026 at 17:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Fengoffice Feng Office Task Title Output add_task.php getTitle cross site scripting
First Time appeared Fengoffice
Fengoffice feng Office
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:fengoffice:feng_office:*:*:*:*:*:*:*:*
Vendors & Products Fengoffice
Fengoffice feng Office
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fengoffice Feng Office
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:45:08.872Z

Reserved: 2026-09-12T08:16:13.257Z

Link: CVE-2026-90497

cve-icon Vulnrichment

Updated: 2026-09-14T15:45:02.899Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T06:16:25.980

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')