Executive brief
Netcad Netigma, a low-code application development platform, contains a security vulnerability that allows attackers to inject malicious scripts into the system. If a user views the affected page, these scripts can execute in their browser, potentially leading to unauthorized data access or account takeover. This could compromise the integrity of the platform and the sensitive business data it manages.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Netcad Netigma versions 6.3.3 through 6.3.5 V8. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious scripts into the application's database, which are then executed in the context of other users' browsers when they access the compromised page. This can lead to session hijacking, unauthorized data modification, or full browser compromise. The vulnerability is exploitable over the network and requires minimal user interaction.
Affected products
- Netcad Software Inc. Netigma 6.3.3 to 6.3.5 V8
Timeline
- 2025-09-23: disclosed
- 2025-09-23: advisory