Executive brief
A security vulnerability exists in Karel ViPort, a communication and port management solution. An attacker with basic user access can inject malicious scripts that are permanently stored on the system. When other users or administrators access the affected pages, these scripts can execute, potentially leading to unauthorized data access, session hijacking, or full system compromise.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Karel Electronics ViPort through version 23012026 due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can submit specially crafted input that is saved on the server and subsequently rendered to other users without proper validation. This can be exploited over the network to steal session cookies, perform actions on behalf of other users, or compromise administrative accounts. The CVSS 3.1 score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Affected products
- Karel Electronics Industry and Trade Inc. ViPort through 23012026
Timeline
- 2026-02-04: disclosed
- 2026-02-04: advisory