Executive brief
Tap&Sign, a digital signature and document management platform, contains a security vulnerability that allows for cross-site scripting (XSS). This could allow an attacker to inject malicious scripts into the web interface, potentially leading to unauthorized actions or the theft of session information. The vendor has not responded to reports of this issue, and no official patch is currently available.
Technical details
A cross-site scripting (XSS) vulnerability exists in Tapandsign Technologies Software Inc. Tap&Sign through version 23012026. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with high privileges can exploit this over the network to inject malicious scripts. According to the CVSS vector, the attack does not require user interaction (UI:N), which is unusual for XSS and may suggest a stored XSS variant that executes automatically for other users. As of the disclosure date, the vendor has not provided a fix.
Affected products
- Tapandsign Technologies Software Inc. Tap&Sign through 23012026
Timeline
- 2026-01-23: advisory: Initial disclosure by USOM/CERT-TR
- 2026-01-23: disclosed: NVD publication date