Executive brief
Worksuite SaaS is a cloud-based HR, CRM, and project management platform used by teams to manage operations. A vulnerability in the Asset Management module allows authenticated administrators to inject malicious code that affects all users who view assets, potentially leading to credential theft and unauthorized account actions.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the Asset Management module of Worksuite SaaS versions prior to 6.0.14. The application fails to properly sanitize user input in the Location and Description fields when creating or editing assets, allowing authenticated administrators to inject arbitrary JavaScript. When other users view the affected asset, the stored malicious script executes in their browsers, enabling session hijacking, credential harvesting, and unauthorized actions performed on behalf of legitimate users. The attack requires high-level admin privileges to inject the payload but affects all users who subsequently view the asset. The vulnerability was fixed in version 6.0.14.
Affected products
- Worksuite Worksuite SaaS prior to 6.0.14
Timeline
- 2026-08-13: disclosed