Junglewise Threat Intelligence

CVE-2026-5220: DivvyDrive Information Technologies DivvyDrive stored XSS

CVE-2026-5220 · Severity: medium · CVSS 6.4 · Published 2026-07-01

Executive brief

DivvyDrive, a file storage and management platform, contains a security flaw that allows attackers to inject malicious scripts into the system. If an attacker saves a specially crafted file or piece of data, these scripts could execute in the browsers of other users or administrators who view that content. This could lead to unauthorized access to user sessions, sensitive data theft, or the performance of actions on behalf of legitimate users.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in DivvyDrive versions 4.8.2.23 through 4.8.3.1. The flaw stems from improper neutralization of user-supplied input (CWE-79) before it is stored and subsequently rendered on web pages. An authenticated attacker with low privileges can exploit this over the network to inject malicious scripts. Because the vulnerability is 'stored,' the payload executes in the context of any user who views the affected page. According to the CVSS vector, the exploit has a changed scope (S:C), meaning it can impact components beyond the vulnerable application itself, such as the user's browser or session cookies. A fix is available in version 4.8.3.1.

Affected products

  • DivvyDrive Information Technologies Inc. DivvyDrive 4.8.2.23 to 4.8.3.1

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats