Cross-Site Scripting Vulnerability in FastBee by kerwincui
CVE-2026-7677
Key Information:
Badges
What is CVE-2026-7677?
A cross-site scripting (XSS) vulnerability exists in the FastBee application from kerwincui affecting versions up to 1.2.1. The issue is found in the System Notice Handler, specifically in the 'Add' function of SysNoticeController.java. An attacker can manipulate the 'noticeContent' argument, enabling remote exploitation of this vulnerability. This weakness allows an attacker to execute arbitrary scripts in the context of a user's session, potentially compromising user data and application integrity. Despite early notification to the vendor regarding this security issue, there has been no response.
Affected Version(s)
FastBee 1.2.0
FastBee 1.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
