PT-2026-50797 · Unknown · Hashgraph Guardian
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hashgraph Guardian versions prior to 3.5.0 commit ba8c566
Description
A stored cross-site scripting issue exists where authenticated users with the
STANDARD REGISTRY role can inject malicious scripts. This occurs by submitting a crafted companyName value through the branding configuration API endpoint. The flaw is caused by an unsanitized innerHTML assignment in the branding service, which allows arbitrary JavaScript to execute in the browser of every authenticated user upon every page load.Recommendations
Update to the version containing commit ba8c566.
Restrict the use of the
companyName variable in the branding configuration API endpoint until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hashgraph Guardian