Junglewise Threat Intelligence

CVE-2026-30082: Ingenico IngEstate Server stored XSS in Software Package List

CVE-2026-30082 · Severity: medium · CVSS 6.1 · Published 2026-03-30

Executive brief

IngEstate Server, a management platform for payment terminals, contains a security flaw that allows attackers to inject malicious scripts into software package descriptions. When an administrator or other user views the affected 'Software Package List' page, the script executes in their browser. This could lead to unauthorized actions being performed on behalf of the user, session hijacking, or the theft of sensitive management credentials.

Technical details

Multiple stored cross-site scripting (XSS) vulnerabilities exist in the Edit feature of the Software Package List page in IngEstate Server v11.14.0. The vulnerability is rooted in the improper neutralization of input within the 'About application', 'What's news', and 'Release note' parameters of the /emgui/rest/appDatasheet/ API endpoint. An attacker can inject malicious JavaScript payloads via a PUT request; these payloads are subsequently stored on the server and executed in the context of any user who views the compromised software package details. Successful exploitation requires the victim to navigate to the affected page but can result in session hijacking or unauthorized administrative actions.

Affected products

  • Ingenico IngEstate Server 11.14.0

Timeline

  • 2026-03-30: disclosed
  • 2026-03-30: advisory

References