Executive brief
Bifra Engineering Consulting Ltd. Q-smart NexT Poll, a digital polling and feedback system, contains a security vulnerability that allows for stored cross-site scripting. An attacker can inject malicious scripts into the application that will execute in the browsers of other users, potentially leading to unauthorized actions or the theft of session information. This could compromise the integrity of the polling data and the privacy of users interacting with the system.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Bifra Engineering Consulting Ltd. Q-smart NexT Poll versions prior to 1.8.7. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious scripts into the application. When a victim views the affected page, the script executes in their browser context, allowing the attacker to access sensitive information like session cookies or perform actions on behalf of the user. The vulnerability is fixed in version 1.8.7.
Affected products
- Bifra Engineering Consulting Ltd. Q-smart NexT Poll before 1.8.7
Timeline
- 2026-07-20: advisory: NVD published the CVE record.
- 2026-07-20: disclosed: Initial disclosure by the Computer Emergency Response Team of the Republic of Turkey.