Description
A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 1.1.3 can resolve this issue. This patch is called 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-19
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting (client‑side)
Action: Apply Patch
AI Analysis

Impact

A flaw was identified in the SearchEngine::buildHighlights method of olivier‑ls PHP‑FTS, where an attacker can manipulate the Query argument to inject malicious script content. This stored cross‑site scripting vulnerability allows the attacker to execute arbitrary JavaScript in the browsers of users who view the affected search results. Based on the description, the attack vector is inferred to involve sending a crafted Query parameter to the search endpoint. The impact is that the attacker could hijack user sessions, steal credentials, or deface the site through client‑side code execution.

Affected Systems

Affected are installations of olivier‑ls PHP‑FTS up to and including version 1.1.2. The vulnerability resides in the src/SearchEngine.php file within the Search Engine component. Any instance of the product that has not been updated to 1.1.3 or later is potentially exposed. System administrators should verify the version currently in use and plan an upgrade if they are running a vulnerable release.

Risk and Exploitability

The CVSS score is 5.1, indicating a moderate severity, and EPSS data is not available. Based on the description, it is inferred that the exploit can be triggered remotely by sending a crafted query to the search endpoint. Because the attack payload is injected into stored content that will be rendered for all users, the risk is significant for sites that expose the search feature to the public or untrusted input.

Generated by OpenCVE AI on September 20, 2026 at 00:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PHP‑FTS to version 1.1.3 or later, which contains the official fix derived from commit 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3.
  • If an immediate upgrade is not feasible, sanitize the Query parameter used by buildHighlights, ensuring that any embedded HTML or script tags are escaped or removed before generating the highlighted output.
  • As a temporary workaround, disable or delete the buildHighlights functionality or restrict access to the SearchEngine API to users with trusted roles until the patch can be applied.

Generated by OpenCVE AI on September 20, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 1.1.3 can resolve this issue. This patch is called 0b2fae333d6b022da7ed4c43e2d41aa03f91dff3. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title olivier-ls PHP-FTS Search SearchEngine.php buildHighlights cross site scripting
First Time appeared Olivier-ls
Olivier-ls php-fts
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:olivier-ls:php-fts:*:*:*:*:*:*:*:*
Vendors & Products Olivier-ls
Olivier-ls php-fts
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Olivier-ls Php-fts
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T15:09:33.949Z

Reserved: 2026-09-19T09:01:13.604Z

Link: CVE-2026-93956

cve-icon Vulnrichment

Updated: 2026-09-21T15:09:20.772Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T23:17:09.707

Modified: 2026-09-21T15:17:36.083

Link: CVE-2026-93956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')