Cross-Site Scripting Flaw in efw4.X by efwGrp
CVE-2026-44259
What is CVE-2026-44259?
The efw4.X framework, developed by efwGrp, is susceptible to a Cross-Site Scripting vulnerability due to improper content handling in its previewServlet. Before version 4.08.010, the framework served files based solely on their MIME type derived from file extensions, lacking adequate content sanitization and necessary security headers. This oversight allows files with extensions such as .html, .htm, or .svg to be served with their respective MIME types, which can lead to the execution of embedded JavaScript in the user’s browser. This flaw enables potential attackers to execute malicious scripts within the application’s origin, posing severe security risks. Users are encouraged to upgrade to version 4.08.010 or later to mitigate this vulnerability.
Affected Version(s)
efw4.X < 4.08.010
