CVE-2026-58475 Details
Description
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output encoding on rendered program names to execute arbitrary JavaScript in the browsers of any users viewing the affected page, with exploitation facilitated by the absence of a required passphrase or the default passphrase 'opendoor'.
A stored cross-site scripting vulnerability has been identified in Sustainable Irrigation Platform (SIP) versions through 5.2.16. This vulnerability allows unauthenticated attackers to inject arbitrary JavaScript by embedding malicious script payloads in program names submitted via HTTP requests. The issue arises from the application's failure to properly encode output for rendered program names, enabling the execution of injected JavaScript in the browsers of users viewing the affected page. Exploitation is made easier by the absence of a required passphrase or the presence of the default passphrase 'opendoor'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/sustainable-irrigation-platform-stored-xss-via-program-name | [email protected] | Third Party Advisory |
| https://www.zeroscience.mk/#/advisories/ZSL-2026-5994 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dan-in-ca sustainable irrigation platform | <= 5.2.16 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |