CVE-2026-11757: Reflected XSS in KA Informatics' Bar Association Website
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS.
This issue affects Bar Association Website: through 18092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be delivered over the network and does not require attacker privileges, but it requires a user to interact with attacker-controlled content or a crafted request.
What is the expected impact if exploitation succeeds?
The reported impact includes low confidentiality and low integrity impact. No availability impact is reported.
Is a vendor fix or workaround available?
No fix or workaround is provided in the available information. The vendor was contacted early about the disclosure but did not respond.