Executive brief
WEBCON BPS, a business process management platform, is affected by a security flaw that allows attackers to execute malicious scripts in a user's browser. By tricking an authenticated user into clicking a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. This could lead to unauthorized access to business workflows and sensitive corporate data.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in WEBCON BPS due to improper neutralization of input in the '/openinmobileapp' endpoint. An unauthenticated remote attacker can craft a malicious URL containing a payload in one of the endpoint's parameters. If an authenticated user visits this URL, the payload is executed within the context of their browser session. This can lead to session hijacking, unauthorized data access, or redirection to malicious sites. The issue is resolved in versions 2026.1.3.109 and 2025.2.1.293.
Affected products
- WEBCON BPS 2026.1.1.45 to 2026.1.3.108, 2025.1.1.87 to 2025.2.1.292
Timeline
- 2026-05-14: disclosed: Vulnerability disclosed by CERT Polska
- 2026-05-14: advisory: NVD record published