CVE-2026-45231: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in DumbWareio DumbAssets
DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers can create or update assets with HTML or JavaScript payloads via the asset API endpoints to execute arbitrary scripts in the browsers of users viewing the asset list, and with Content-Security-Policy disabled, the injected scripts can make unrestricted connections to internal network services.
AI Analysis
Technical Summary
CVE-2026-45231 is a stored cross-site scripting vulnerability in DumbWareio's DumbAssets product affecting versions up to 1.0.11. The flaw exists because asset fields such as name, description, modelNumber, serialNumber, and tags are stored without server-side sanitization and rendered using innerHTML without escaping on the client side. Attackers can exploit this by creating or updating assets through the API with malicious scripts that execute in users' browsers when viewing the asset list. The lack of Content-Security-Policy enforcement can further enable these scripts to perform unrestricted network requests internally. No official remediation or patch has been indicated in the available data.
Potential Impact
Successful exploitation allows attackers to execute arbitrary scripts in the browsers of users who view the affected asset data. This can lead to theft of session tokens, unauthorized actions on behalf of users, or network reconnaissance if Content-Security-Policy is disabled. The vulnerability does not require privileges or authentication to exploit and has a medium severity rating based on CVSS 4.0 scoring.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider enabling strict Content-Security-Policy headers to restrict script execution and network requests. Additionally, avoid disabling client-side security controls and monitor API usage for suspicious asset creation or updates containing HTML or JavaScript payloads.
CVE-2026-45231: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in DumbWareio DumbAssets
Description
DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side sanitization and rendered using innerHTML without client-side escaping. Attackers can create or update assets with HTML or JavaScript payloads via the asset API endpoints to execute arbitrary scripts in the browsers of users viewing the asset list, and with Content-Security-Policy disabled, the injected scripts can make unrestricted connections to internal network services.
CVSS v4.0
Score 5.3medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-45231 is a stored cross-site scripting vulnerability in DumbWareio's DumbAssets product affecting versions up to 1.0.11. The flaw exists because asset fields such as name, description, modelNumber, serialNumber, and tags are stored without server-side sanitization and rendered using innerHTML without escaping on the client side. Attackers can exploit this by creating or updating assets through the API with malicious scripts that execute in users' browsers when viewing the asset list. The lack of Content-Security-Policy enforcement can further enable these scripts to perform unrestricted network requests internally. No official remediation or patch has been indicated in the available data.
Potential Impact
Successful exploitation allows attackers to execute arbitrary scripts in the browsers of users who view the affected asset data. This can lead to theft of session tokens, unauthorized actions on behalf of users, or network reconnaissance if Content-Security-Policy is disabled. The vulnerability does not require privileges or authentication to exploit and has a medium severity rating based on CVSS 4.0 scoring.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider enabling strict Content-Security-Policy headers to restrict script execution and network requests. Additionally, avoid disabling client-side security controls and monitor API usage for suspicious asset creation or updates containing HTML or JavaScript payloads.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-05-11T14:14:49.612Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a0b633fec166c07b0e6172b
Added to database: 05/18/2026, 19:06:39 UTC
Last enriched: 07/15/2026, 10:01:29 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.