Junglewise Threat Intelligence

CVE-2026-34907: Simple SA Wirtualna Uczelnia Reflected XSS in locale parameter

CVE-2026-34907 · Severity: info · CVSS 5.1 · Published 2026-06-02

Executive brief

Wirtualna Uczelnia is a web portal used by universities to manage student records, grades, and academic schedules. A security flaw in how the portal handles language settings allows attackers to execute malicious scripts in a user's browser. If a student or staff member clicks a specially crafted link, an attacker could potentially steal login session information or perform unauthorized actions on their behalf within the university system.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Simple SA Wirtualna Uczelnia due to improper neutralization of user input in the 'locale' parameter. The vulnerability is present across multiple endpoints where the application fails to adequately sanitize or encode this parameter before reflecting it in the web page generation. An unauthenticated remote attacker can exploit this by tricking a victim into clicking a malicious URL containing embedded JavaScript. Successful exploitation allows the execution of arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The issue affects all versions up to and including wu#2016.437.295#0#20260327_105545.

Affected products

  • Simple SA Wirtualna Uczelnia up to wu#2016.437.295#0#20260327_105545

Timeline

  • 2026-06-02: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-06-02: advisory

References

Related threats