Junglewise Threat Intelligence

CVE-2026-6283: DivvyDrive Information Technologies DivvyDrive stored XSS

CVE-2026-6283 · Severity: medium · CVSS 5.4 · Published 2026-07-01

Executive brief

DivvyDrive, a file storage and collaboration platform, is affected by a security flaw that allows attackers to inject malicious scripts into the application. If a user views the compromised content, the attacker could potentially steal session information or perform actions on the user's behalf. Organizations should update to version 4.8.3.1 or later to resolve this issue.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in DivvyDrive versions 4.8.2.23 through 4.8.3.0. The flaw stems from improper neutralization of user-supplied input, allowing an authenticated attacker with low privileges to inject malicious scripts into web pages generated by the application. When other users (including administrators) view the affected page, the script executes in their browser context. This can lead to session hijacking, unauthorized data access, or redirection to malicious sites. The issue is addressed in version 4.8.3.1.

Affected products

  • DivvyDrive Information Technologies Inc. DivvyDrive v.4.8.2.23 before v.4.8.3.1

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References

Related threats