Executive brief
A cross-site scripting (XSS) vulnerability exists in IT's Workif, a business management platform. This flaw could allow an attacker to inject malicious scripts into the application, potentially leading to unauthorized access to user sessions or the theft of sensitive information. The vendor has not yet responded to reports of this issue, and no official patch is currently available.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Isin Basi Advertisement Information Technologies Trade Inc. IT's Workif through version 20251003. The vulnerability stems from improper neutralization of user-supplied input during web page generation. According to the CVSS vector, exploitation requires high privileges and occurs over the network under high complexity conditions. Successful exploitation could allow an attacker to execute arbitrary scripts in the context of a user's browser session. As of the disclosure date, the vendor has not responded to the report, and no fix has been confirmed.
Affected products
- Isin Basi Advertisement Information Technologies Trade Inc. IT's Workif through 20251003
Timeline
- 2025-10-03: disclosed: Vulnerability published by TR-CERT (USOM)
- 2025-10-03: advisory: NVD published the CVE record