Junglewise Threat Intelligence

CVE-2026-5738: BilPark Informatics DoXBASE cross-site scripting

CVE-2026-5738 · Severity: medium · CVSS 6.1 · Published 2026-08-27

Executive brief

DoXBASE is a document management system used by organizations to store and display content. A cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user sessions, stealing credentials, or defacing content without requiring any special privileges.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw arising from improper neutralization of user-supplied input during web page generation in DoXBASE. An attacker can craft malicious input containing JavaScript code that, when processed and rendered by the application, executes in the browser of any user viewing the affected page. This is a reflected or stored XSS attack depending on how the application processes input. The attack requires the victim to visit a specially crafted URL or view content containing the injected payload; no authentication is typically required. Exploitation allows session hijacking, credential theft, or malware delivery. Patch status should be verified with the vendor; note that the vendor did not respond to early disclosure attempts.

Affected products

  • BilPark Informatics Technologies DoXBASE through 27082026

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: advisory: NVD and Turkish Cyber Security Authority advisory published

References