Junglewise Threat Intelligence

CVE-2026-58475: Dan-in-CA Sustainable Irrigation Platform stored XSS in program names

CVE-2026-58475 · Severity: medium · CVSS 6.1 · Published 2026-07-14

Technologies: Dan-in-CA Sustainable Irrigation Platform. Vendors: Dan-in-CA.

Executive brief

The Sustainable Irrigation Platform (SIP), a system used for managing irrigation programs, is vulnerable to a security flaw where attackers can inject malicious scripts into the platform. By submitting a specially crafted program name, an attacker can execute unauthorized code in the web browsers of legitimate users who view the affected page. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information, especially if the system is using the default 'opendoor' password.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The flaw is located in the handling of program names submitted via HTTP requests, which are subsequently rendered without proper output encoding. An unauthenticated attacker can exploit this by injecting malicious JavaScript payloads into the program name field. The attack is facilitated by the lack of a required passphrase or the use of the default passphrase 'opendoor'. When an administrative user or any other user views the page containing the malicious program name, the script executes in their browser context, potentially allowing for session hijacking or unauthorized configuration changes.

Affected products

  • Dan-in-CA Sustainable Irrigation Platform (SIP) through 5.2.16

Timeline

  • 2026-07-14: advisory: Initial disclosure by VulnCheck and Zero Science Lab
  • 2026-07-14: disclosed

References

Related threats