Executive brief
A security vulnerability has been identified in the Global Interactive Design Media Content Management System (CMS), a platform used for managing website content. This flaw allows attackers to inject malicious scripts into the website by manipulating technical data sent in web requests. If exploited, this could lead to unauthorized actions being performed in a user's browser or the theft of sensitive session information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Global Interactive Design Media Software Inc. Content Management System (CMS) due to improper neutralization of input during web page generation. Specifically, the application fails to sanitize data received through HTTP headers before reflecting it in the output. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP headers to the server. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The vulnerability affects versions through 21072025.
Affected products
- Global Interactive Design Media Software Inc. Content Management System (CMS) through 21072025
Timeline
- 2026-01-29: advisory: Initial advisory published by USOM/TR-CERT
- 2026-01-29: disclosed