CVE-2026-6002
8.8DivvyDrive Information Technologies Inc · DivvyDrive
A cross-site scripting vulnerability in DivvyDrive allows unauthenticated attackers to execute arbitrary scripts via improperly neutralized HTML tags.
Executive summary
A cross-site scripting vulnerability in DivvyDrive versions 4.8.2.9 through 4.8.3.1 allows remote attackers to execute arbitrary script code, resulting in potential session hijacking and data theft.
Vulnerability
This is an improper neutralization of script-related HTML tags vulnerability, categorized as CWE-80, affecting web input handling. The attack vector is network-based and requires user interaction, but does not require authentication.
Business impact
A successful exploit allows malicious actors to execute arbitrary scripts in the context of a victim session, potentially leading to unauthorized access to sensitive user data, session token theft, or administrative account takeover. Although the CVSS score of 8.8 reflects high severity due to high confidentiality, integrity, and impact metrics in certain configurations, the requirement for user interaction slightly reduces the overall direct automatability of the threat.
Remediation
Immediate Action: Update DivvyDrive to version 4.8.3.2 or later immediately to resolve the cross-site scripting flaw.
Proactive Monitoring: Monitor web server and application access logs for unusual parameter inputs containing script tags or suspicious user interaction patterns.
Compensating Controls: Implement a strict Content Security Policy and deploy Web Application Rules to detect and block reflected or stored cross-site scripting payloads.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Organizations utilizing DivvyDrive must treat this vulnerability with high urgency despite the requirement for user interaction. Administrators should apply the vendor-supplied update to version 4.8.3.2 or later immediately to eliminate the underlying input validation weakness and protect user sessions from compromise.
More DivvyDrive Information Technologies Inc CVEs
Sources
Originally found and disclosed by Alperen KESKİN, per the CVE Program record.