Stored Cross-site Scripting Vulnerability in maalfer Pentestify
CVE-2026-59238
6.9MEDIUM
What is CVE-2026-59238?
A vulnerability in maalfer Pentestify prior to version 1.1.0 allows authenticated attackers to exploit stored cross-site scripting. By injecting malicious JavaScript into the client-side report rendering functions, an attacker can manipulate the display of findings images or client logos. This unsanitized data is then rendered into an src attribute, enabling the execution of arbitrary JavaScript in the browsers of users who access affected reports, potentially compromising sensitive information and user session data. Immediate action is recommended to secure your application.
Affected Version(s)
Pentestify 0 < 1.1.0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marcos GarcĂa (s3ntinl)
Mario Ălvarez FernĂĄndez
XoĂĄn M. Otero Jorge
Secur0 CNA
