{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-6179","assignerOrgId":"5ac195ad-69e7-48e7-9c1e-bfc958c39761","state":"PUBLISHED","assignerShortName":"FSOFT","dateReserved":"2026-04-13T02:18:11.562Z","datePublished":"2026-04-13T02:27:53.206Z","dateUpdated":"2026-04-13T18:06:17.801Z"},"containers":{"cna":{"providerMetadata":{"orgId":"5ac195ad-69e7-48e7-9c1e-bfc958c39761","shortName":"FSOFT","dateUpdated":"2026-04-13T02:27:53.206Z"},"title":"Stored Cross Site Scripting in NightWolf Penetration Testing Platform","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-79","description":"CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-592","descriptions":[{"lang":"en","value":"CAPEC-592 Stored XSS"}]}],"affected":[{"vendor":"FPT Software","product":"NightWolf Penetration Testing Platform","versions":[{"status":"affected","version":"2.1.5"},{"status":"unaffected","version":"2.1.6"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser","supportingMedia":[{"type":"text/html","base64":false,"value":"Stored Cross Site Scripting in NightWolf Penetration Testing Platform allows attack trigger and run malicious script in user's browser"}]}],"references":[{"url":"https://bug.report.night-wolf.io/changelogs"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N"}}],"timeline":[{"time":"2026-04-11T10:00:00.000Z","lang":"en","value":"The reporter submits the vulnerability to security_report@fpt.com."},{"time":"2026-04-12T11:00:00.000Z","lang":"en","value":"The security team verifies the issue and provides a fixing solution."},{"time":"2026-04-13T01:00:00.000Z","lang":"en","value":"The security team releases the fix, retests the issue, and closes the vulnerability."},{"time":"2026-04-13T02:00:00.000Z","lang":"en","value":"Assign a CVE to the reporter."}],"credits":[{"lang":"en","value":"Phan Cong Anh Tuan (phanconganhtuan2003@gmail.com)","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.1"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-6179","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-04-13T17:36:38.518612Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-04-13T18:06:17.801Z"}}]}}