Executive brief
Ragic Enterprise Cloud Database, a platform used by businesses to build custom database applications, is affected by a security flaw that allows attackers to inject malicious scripts into the system. If a user views a compromised page, these scripts execute automatically in their web browser. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Ragic Enterprise Cloud Database due to improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by submitting malicious JavaScript code that becomes permanently stored on the server. When other users navigate to the affected page, the script executes within the context of their browser session. This can be used to steal session cookies, perform unauthorized actions, or redirect users to malicious sites. The cloud-hosted version has been mitigated by the vendor, but on-premises installations require a patch released on or after April 10, 2026.
Affected products
- Ragic Enterprise Cloud Database All versions prior to April 10, 2026 patch (on-premises)
Timeline
- 2026-04-10: patched: Patch released for on-premises versions
- 2026-07-13: advisory: TWCERT/CC advisory published
- 2026-07-13: disclosed: CVE published to NVD dataset