Executive brief
CityPLus, a software solution by Beyaz Computer, is vulnerable to a security flaw that allows attackers to inject malicious scripts into web pages viewed by other users. If a user clicks a specially crafted link, an attacker could potentially steal session information, perform actions on behalf of the user, or disrupt the application's availability. This issue has been addressed in version V24.29750.1.0.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Beyaz Computer CityPLus versions prior to V24.29750.1.0. The application fails to properly neutralize user-supplied input before including it in generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in unauthorized access to sensitive data, session hijacking, or impact on service availability. The vulnerability is patched in version V24.29750.1.0.
Affected products
- Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus before V24.29750.1.0
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory