Executive brief
DernekWeb, a management platform for associations and organizations, is vulnerable to a security flaw that allows malicious scripts to be permanently stored on its web pages. If an administrator or user views an affected page, an attacker could hijack their session, steal sensitive organizational data, or perform unauthorized actions. This could lead to a full compromise of the platform's integrity and confidentiality.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Basamak Information Technology DernekWeb through version 30122025 due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can inject malicious JavaScript into the application, which is then stored on the server and executed in the browser of any user who views the affected content. Given the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), the vulnerability requires minimal user interaction and can lead to a complete compromise of confidentiality, integrity, and availability for the affected user session. Organizations using DernekWeb should contact the vendor for patching information.
Affected products
- Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb through 30122025
Timeline
- 2026-05-18: advisory: CVE published by TR-CERT and NVD