Junglewise Threat Intelligence

CVE-2026-27787: ICZ Corporation MATCHA SNS cross-site scripting

CVE-2026-27787 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Executive brief

ICZ Corporation's MATCHA SNS, a social networking platform, contains a security flaw that allows attackers to run malicious scripts in other users' browsers. By tricking a user into viewing a compromised profile or file, an attacker could steal login session cookies, impersonate users, or deface website content. This could lead to unauthorized account access and reputational damage for organizations using the software.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in MATCHA SNS versions 1.3.9 and earlier due to improper neutralization of user-supplied input. An authenticated attacker can inject malicious scripts into fields such as profile names or filenames. When other users view the affected profile or file, the script executes in their browser context. This can result in the theft of session cookies (account takeover) or unauthorized modification of the page content. The vulnerability is addressed in version 1.3.10.

Affected products

  • ICZ Corporation MATCHA SNS 1.3.9 and earlier

Timeline

  • 2026-04-07: patched: Vendor released version 1.3.10 to address the vulnerability.
  • 2026-04-08: disclosed: Public advisory published by JVN and NVD.

References