CVE-2026-8403 Details
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 allows Stored XSS. This issue affects SYSGUARD 6001: from 2.0.2 before 6.1.4.0. NOTE: The vendor was contacted and it was learned that the product is not supported.
A stored cross-site scripting vulnerability has been identified in Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD version 6001, specifically in the range from 2.0.2 prior to 6.1.4.0. This vulnerability arises from improper neutralization of input during web page generation, allowing attackers to inject malicious scripts that are permanently stored and executed in the context of the user.
The vendor has discontinued support for this product. Users are advised to switch to an alternative software.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0467 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 | >= 2.0.2, < 6.1.4.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion