PT-2026-48267 · Brian Ruf · Oscal-Gui

Philopentest

+1

·

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-34416

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the project request parameter. Attackers can craft a malicious URL containing unsanitized input that breaks out of the JavaScript string and HTML attribute context in the body onload event handler to execute arbitrary scripts when the link is visited by a victim.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-34416

Affected Products

Oscal-Gui