PT-2026-43211 · Xibo Cms · Xibo Cms
CVE-2026-42558
·
Published
2026-05-26
·
Updated
2026-06-11
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Xibo CMS versions prior to 4.4.2
Description
A vulnerability chain involving Stored Cross-Site Scripting (XSS) and Iframe Sandbox escape exists in the Xibo CMS. Users with DataSet permissions can utilize the Data Connector functionality to craft messages that escape the sandbox and facilitate XSS. This exploitation requires an authorized user to possess specific privileges, such as the ability to use the "Add DataSet" button to create DataSets independently of Layouts, which are typically not granted to non-administrators by default.
Recommendations
Upgrade to version 4.4.2.
Revoke privileges related to the "Add DataSet" button from untrusted users as a temporary mitigation.
Exploit
Fix
XSS
Origin Validation Error
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xibo Cms