Executive brief
A security vulnerability exists in the NightWolf Penetration Testing Platform, a tool used by security professionals to manage and conduct security assessments. An attacker can inject malicious scripts into the platform that execute when other users view specific pages. This could lead to unauthorized actions being performed in a user's browser or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the NightWolf Penetration Testing Platform version 2.1.5 due to improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious JavaScript into the application's database. When an administrative or authorized user subsequently views the affected page, the script executes within the context of their session. This can lead to session hijacking, unauthorized data modification, or further exploitation of the platform's users. The issue is addressed in version 2.1.6.
Affected products
- FPT Software NightWolf Penetration Testing Platform 2.1.5
Timeline
- 2026-04-12: disclosed
- 2026-04-13: advisory
- 2026-06-17: patched: Version 2.1.6 listed as unaffected status.