Executive brief
SHIRASAGI is a web-based content management and groupware platform. A cross-site scripting vulnerability in the guided procedures feature allows attackers to execute malicious scripts in the browsers of users who view crafted procedure links, potentially leading to session hijacking, credential theft, or unauthorized data access.
Technical details
A cross-site scripting (CWE-79) vulnerability exists in SHIRASAGI's guided procedures feature. The vulnerability arises from insufficient input validation on procedure link URLs, allowing an authenticated administrator to inject malicious JavaScript code that executes in the context of end users' browsers when they access the affected procedures. Attack requires prior authentication to the CMS admin panel and social engineering to trick users into viewing the malicious procedure. An attacker can achieve script execution to steal cookies, session tokens, or perform actions on behalf of the victim user. The vulnerability affects versions v1.14.0 through v1.20.2 and is fixed in v1.21.0.
Affected products
- SHIRASAGI Project SHIRASAGI v1.14.0 to v1.20.2
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: v1.21.0 released