Executive brief
A stored cross-site scripting vulnerability exists in the Twiser OKRs & Goals platform, a tool used by organizations to track business objectives and employee performance. An attacker with basic user access can inject malicious scripts into the platform that execute when other users view specific pages. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Twiser OKRs & Goals due to improper neutralization of user-supplied input during web page generation. The flaw is tracked as CWE-79 and allows a remote attacker with low privileges to inject malicious JavaScript into the application. The attack requires a victim to interact with the affected page (UI:R) and has a changed scope (S:C), potentially allowing the attacker to access session tokens or perform actions in the context of other users. The issue is resolved in version 28398.
Affected products
- Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals 28220 to 28398
Timeline
- 2026-07-09: advisory: Advisory published by TR-CERT and NVD