Cross-Site Scripting Vulnerability in Talassoft Industrial Management Software by TMT Machinery Industry and Trade Co. Ltd.
CVE-2026-92085

5.4MEDIUM

What is CVE-2026-92085?

A vulnerability in Talassoft Industrial Management Software affects the sanitization of user inputs during web page generation, allowing attackers to execute stored cross-site scripting (XSS) exploits. This issue enables unauthorized users to inject malicious scripts into web pages, potentially compromising sensitive user data and leading to further security breaches. The vulnerability impacts versions prior to 16.0.1, emphasizing the need for users to update to ensure robust security against such threats.

Affected Version(s)

Talassoft Industrial Management Software 0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Samet Yılmaz
.