Executive brief
Netigma, a web-based application development platform, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages viewed by other users. By tricking a user into clicking a specially crafted link, an attacker could steal login session information or perform unauthorized actions on the user's behalf. This could lead to unauthorized access to sensitive business data managed within the platform.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in Netcad Netigma due to improper neutralization of input during web page generation. The vulnerability is triggered through malicious payloads embedded in HTTP query strings. An unauthenticated remote attacker can exploit this by inducing a user to visit a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to capture session cookies or manipulate page content. The issue is fixed in version 6.3.5 V8.
Affected products
- Netcad Software Inc. Netigma From 6.3.5 before 6.3.5 V8
Timeline
- 2025-11-06: disclosed
- 2025-11-06: advisory