Junglewise Threat Intelligence

CVE-2026-35403: aces LORIS cross-site scripting in survey_accounts module

CVE-2026-35403 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Aces Loris.

Executive brief

LORIS, a web-based platform for managing neuroimaging research data, contains a security flaw in its survey management module. An attacker could trick a researcher or staff member into clicking a malicious link, allowing the attacker to run unauthorized scripts in the victim's browser. This could lead to the theft of sensitive research data or the hijacking of user sessions.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the survey_accounts module of LORIS. The root cause is a failure to set the 'Content-Type: application/json' header in the ValidateEmailSubmitInput.php component. Although the output data is JSON-encoded, the absence of the header causes browsers to perform MIME-sniffing and interpret the payload as HTML. An attacker with low privileges can exploit this by inducing a user to follow a link containing an invalid visit label. This can result in the execution of arbitrary JavaScript in the context of the victim's session. The issue is resolved in versions 27.0.3 and 28.0.1 by explicitly setting the correct JSON Content-Type header.

Affected products

  • aces Loris >= 15.10, < 27.0.3; 28.0.0

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References