PT-2026-34595 · Unknown · Stig-Manager
Published
2026-04-23
·
Updated
2026-04-23
·
CVE-2026-41200
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
STIG Manager versions 1.5.10 through 1.6.7
Description
Reflected Cross-Site Scripting (XSS) occurs in the OIDC authentication error handling code within
src/init.js and public/reauth.html. During the OIDC redirect flow, the error and error description query parameters returned by the OIDC provider are written directly to the DOM via innerHTML without HTML escaping. This allows an attacker to execute arbitrary JavaScript in the application origin context by convincing a user to follow a malicious redirect URL. If the user has an active session in another tab, the injected code can communicate with the SharedWorker managing the access token to perform authenticated API requests, such as reading and modifying collection data.Recommendations
Update to version 1.6.8.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stig-Manager