Description
Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report via a payload stored in a finding's images array or a report's client_logo array, which is interpolated into an <img> src attribute without escaping.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to version 1.1.0 or higher.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 20 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker to execute arbitrary JavaScript in the browser of any user who views an affected report via a payload stored in a finding's images array or a report's client_logo array, which is interpolated into an <img> src attribute without escaping. | |
| Title | Stored XSS in Pentestify via unsanitized finding images and report client logo | |
| First Time appeared |
Maalfer
Maalfer pentestify |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:maalfer:pentestify:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Maalfer
Maalfer pentestify |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-07-20T15:06:54.041Z
Reserved: 2026-07-03T11:24:39.242Z
Link: CVE-2026-59238
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses