CVE-2026-24662
Description
Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script may be executed on a user's web browser when viewing the administration page showing the information of the file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Musetheque V4 Information Disclosure allows arbitrary script execution via malicious file upload when viewed in admin page.
Vulnerability
Overview
CVE-2026-24662 is a stored cross-site scripting (XSS) vulnerability in Fujitsu Japan Limited's Musetheque V4 Information Disclosure for IPKNOWLEDGE, affecting versions V4L1 rev2203.0 and earlier. The root cause is insufficient sanitization of file content during upload, allowing an attacker to inject arbitrary scripts into the application [1].
Exploitation
Conditions
An attacker with low privileges can upload a file containing malicious JavaScript. The script is then executed when an administrator views the file's information page, requiring user interaction (UI:R) from the victim. The attack vector is network-based (AV:N) and does not require advanced authentication [1].
Impact
Successful exploitation enables arbitrary script execution in the context of the admin's browser, potentially leading to session hijacking, data exfiltration, or unauthorized actions. The CVSS v3 base score is 5.4 (Medium), reflecting the need for user interaction and limited scope of impact [1].
Mitigation
Fujitsu Japan Limited has released version V4L1 rev2603.1, which addresses this vulnerability. Users are advised to update to the latest version as soon as possible. No workarounds are documented [1].
AI Insight generated by deepseek/deepseek-v4-flash-20260423 on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= rev2203.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.