Junglewise Threat Intelligence

CVE-2026-13536: GotoHTTP cross site scripting in /reg.12x endpoint

CVE-2026-13536 · Severity: medium · CVSS 4.3 · Published 2026-06-29

Executive brief

GotoHTTP, a remote control platform, contains a security flaw that could allow an attacker to execute malicious scripts in a user's web browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on the user's behalf. While the vendor has addressed the underlying code, they have indicated that the specific vulnerable web address is not typically exposed to users in normal operations.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in GotoHTTP versions up to 10.2 within the /reg.12x endpoint. The vulnerability is caused by improper sanitization of the 'sn' GET parameter, which is echoed back to the client in an error message without sufficient HTML encoding. An unauthenticated remote attacker can exploit this by crafting a URL containing a malicious script payload. If a victim visits this URL, the script executes within their browser context, potentially allowing for session hijacking or credential theft. The vendor has removed the unnecessary parameter echo in the source code, though a formal version update including this fix is pending.

Affected products

  • GotoHTTP GotoHTTP up to 10.2

Timeline

  • 2026-05-29: disclosed: Initial disclosure on GitHub
  • 2026-06-29: advisory: NVD/VulDB publication date

References