Stored Cross-Site Scripting Vulnerability in Verba Management System
CVE-2026-21730
5.3MEDIUM
What is CVE-2026-21730?
The Verba Management System contains a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthorized user attempts to log in with an invalid username and password, the provided username is logged by the system. Because of inadequate input sanitization, this exposes a vector for an attacker to inject a harmful XSS payload into the username field. If the administrator then accesses the log viewer, the malicious payload is executed within the context of the admin's browser, potentially compromising the security of the application and its users.
Affected Version(s)
Verba 0 < 10.0.6
