Executive brief
Armiya Information Technologies' Access Control System (GKS), used for managing physical security and entry points, is vulnerable to a security flaw where malicious scripts can be stored on the system. If an administrator or user views the affected page, these scripts could execute in their browser, potentially leading to unauthorized data access or session hijacking. This issue is resolved in Version 2 of the software.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Armiya Information Technologies Access Control System (GKS) prior to Version 2. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). A remote, unauthenticated attacker can inject malicious scripts into the application's database, which are then executed in the context of a victim's browser session when they navigate to the affected page. This can lead to information disclosure or unauthorized actions performed on behalf of the victim. The vulnerability is addressed in Version 2.
Affected products
- Armiya Information Technologies Ltd. Co. Access Control System (GKS) before Version 2
Timeline
- 2026-07-07: advisory: NVD publication date
- 2026-07-07: disclosed: TR-CERT advisory published