Executive brief
XMLRPC-C is a software library used by developers to enable different computer programs to communicate with each other over the internet. A security flaw in its error-reporting component allows attackers to perform reflected cross-site scripting (XSS) attacks. If an unsuspecting user clicks a malicious link, an attacker could execute unauthorized scripts in the user's browser, potentially leading to the theft of sensitive session information or unauthorized actions on the user's behalf.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the error page component of the XMLRPC-C library (versions 1.07 through 1.67.01). The flaw stems from improper neutralization of user-supplied input during the generation of web-based error messages (CWE-79). An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to disclose sensitive information such as session tokens. While the NVD entry lists the severity as 'info', the contributing CNA (The Missing Link Australia) has assigned a CVSS 4.0 score of 8.2.
Affected products
- XMLRPC-C XMLRPC-C 1.07 through 1.67.01
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory