Executive brief
giSoft City Guide, a web application used for providing local information and navigation, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the pages viewed by other users. If a user clicks on a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. This issue has been addressed in version 1.4.45.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in giSoft Information Technologies City Guide versions prior to 1.4.45. The application fails to properly neutralize user-supplied input before including it in generated web pages. An unauthenticated remote attacker can exploit this by tricking a user into visiting a malicious URL containing a crafted payload. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized data access. The vulnerability is resolved in version 1.4.45.
Affected products
- giSoft Information Technologies City Guide before 1.4.45
Timeline
- 2025-10-21: disclosed
- 2025-10-21: advisory