PT-2026-3073 · Unknown · Lasuite Doc
Thxtech
·
Published
2026-01-15
·
Updated
2026-03-12
·
CVE-2026-22867
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LaSuite Doc versions 3.8.0 through 4.3.0
Description
LaSuite Doc is a collaborative note taking, wiki and documentation platform. A Stored Cross-Site Scripting (XSS) issue exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacker with document editing privileges can inject a malicious javascript: URL that executes arbitrary code when other users click on the link.
Recommendations
Update LaSuite Doc to version 4.4.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lasuite Doc