CVE-2026-13536: Cross Site Scripting in GotoHTTP
A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "We immediately removed unnecessary parameter echo from source code. However the URL in the issue description will never be used in browser nor exposed to user, so it will not bring secure problem in fact. So we don't upgrade server right now, it will be included in next version together with other features."
AI Analysis
Technical Summary
This vulnerability involves a cross-site scripting flaw in GotoHTTP up to version 10.2, specifically related to the handling of the 'sn' parameter in the /reg.12x endpoint. The vendor removed unnecessary parameter echoing from the source code but has not issued an immediate patch, citing that the affected URL is not exposed to users or browsers, thus reducing the security impact. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity) and is remotely exploitable without privileges or user interaction. No official remediation or patch is currently available, and the vendor plans to address the issue in a future version.
Potential Impact
The vulnerability allows remote attackers to perform cross-site scripting via the 'sn' parameter in the /reg.12x file. However, the vendor indicates that the affected URL is not exposed to end users or browsers, which limits the practical impact of this vulnerability. No known exploits are reported in the wild. The CVSS score of 5.3 reflects a medium severity risk with potential limited impact due to the usage context described by the vendor.
Mitigation Recommendations
Currently, there is no official patch or upgrade available for this vulnerability. The vendor has removed unnecessary parameter echoing in the source code but has not released an immediate fix, stating the affected URL is not exposed to users or browsers. The vendor plans to include a fix in the next version along with other features. Users should monitor vendor communications for the upcoming release and consider mitigating exposure to the /reg.12x endpoint if possible until the fix is available.
CVE-2026-13536: Cross Site Scripting in GotoHTTP
Description
A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "We immediately removed unnecessary parameter echo from source code. However the URL in the issue description will never be used in browser nor exposed to user, so it will not bring secure problem in fact. So we don't upgrade server right now, it will be included in next version together with other features."
CVSS v4.0
Score 5.3medium
Affected software
cpe:2.3:a:gotohttp:gotohttp:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a cross-site scripting flaw in GotoHTTP up to version 10.2, specifically related to the handling of the 'sn' parameter in the /reg.12x endpoint. The vendor removed unnecessary parameter echoing from the source code but has not issued an immediate patch, citing that the affected URL is not exposed to users or browsers, thus reducing the security impact. The vulnerability has a CVSS 4.0 base score of 5.3 (medium severity) and is remotely exploitable without privileges or user interaction. No official remediation or patch is currently available, and the vendor plans to address the issue in a future version.
Potential Impact
The vulnerability allows remote attackers to perform cross-site scripting via the 'sn' parameter in the /reg.12x file. However, the vendor indicates that the affected URL is not exposed to end users or browsers, which limits the practical impact of this vulnerability. No known exploits are reported in the wild. The CVSS score of 5.3 reflects a medium severity risk with potential limited impact due to the usage context described by the vendor.
Mitigation Recommendations
Currently, there is no official patch or upgrade available for this vulnerability. The vendor has removed unnecessary parameter echoing in the source code but has not released an immediate fix, stating the affected URL is not exposed to users or browsers. The vendor plans to include a fix in the next version along with other features. Users should monitor vendor communications for the upcoming release and consider mitigating exposure to the /reg.12x endpoint if possible until the fix is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-28T09:31:19.810Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4200db27e9c7971948c615
Added to database: 06/29/2026, 05:21:31 UTC
Last enriched: 07/06/2026, 22:22:35 UTC
Last updated: 08/12/2026, 12:41:08 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.