Executive brief
Rolantis Agentis is a web-based platform used in tourism management. The vulnerability allows an attacker to inject malicious scripts that execute in users' browsers when they interact with affected web pages, potentially stealing session cookies, account credentials, or sensitive data visible to the user.
Technical details
The vulnerability is an improper input neutralization flaw (CWE-79) allowing cross-site scripting (XSS) attacks targeting HTML attributes. Exploitation requires the attacker to craft a malicious input that bypasses sanitization and becomes embedded in HTML attribute context. This is a stored or reflected XSS depending on how user input is processed; successful exploitation grants the attacker arbitrary JavaScript execution in victim browsers with the privileges of the authenticated user.
Affected products
- Rolantis Information Technologies Agentis 4.44 to before 4.6
Timeline
- 2026-09-28: disclosed