CVE-2026-6623 Details
Description
A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way.
A stored cross-site scripting vulnerability has been identified in BichitroGan ISP Billing Software version 2025.3.20. The issue arises in the Profile Page Handler component, specifically within the file '/?_route=settings/users-view/' . This vulnerability allows users to inject malicious JavaScript into the 'fullname' field, which is then executed in the browsers of users viewing the affected page, including administrators. The injection occurs because the application fails to properly encode output before rendering it, enabling the execution of harmful scripts.
It is recommended to escape output using proper encoding functions, validate input to restrict special characters, and implement consistent output encoding across all templates.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 20, 2026CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/4m3rr0r/PoCVulDb/issues/17 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/submit/792394 | [email protected] | Technical Description |
| https://vuldb.com/vuln/358258 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/vuln/358258/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BichitroGan ISP Billing Software | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |
Volerion