Junglewise Threat Intelligence

CVE-2026-29598: DDSN Interactive Acora CMS stored XSS in user management endpoints

CVE-2026-29598 · Severity: medium · CVSS 5.4 · Published 2026-04-01

Technologies: DDSN Interactive Acora CMS. Vendors: DDSN Interactive.

Executive brief

DDSN Interactive Acora CMS, a content management system used for website administration, contains a security flaw in its user management component. An attacker with basic user-creation privileges can inject malicious scripts into user profile fields like names. When other administrators view these profiles, the scripts execute, potentially allowing the attacker to hijack sessions, steal credentials, or perform unauthorized actions on the website.

Technical details

Multiple stored cross-site scripting (XSS) vulnerabilities exist in the submit_add_user.asp and submit_edit_user.asp endpoints of DDSN Interactive Acora CMS v10.7.1. The vulnerability is caused by improper neutralization of input in the 'First Name' and 'Last Name' parameters. An attacker with low-level administrative privileges can inject a crafted JavaScript payload that is stored in the application's database. The payload executes in the browser of any user (typically higher-privileged administrators) who views the affected user records. This can lead to session hijacking, unauthorized data modification, or credential theft. A proof-of-concept has been disclosed, but official patch information is not currently detailed in the advisory.

Affected products

  • DDSN Interactive Acora CMS 10.7.1

Timeline

  • 2026-04-01: disclosed: Vulnerability disclosed by Joby Y Daniel from Crowe India
  • 2026-04-01: advisory: NVD published CVE-2026-29598

References

Related threats