CVE-2026-75307: XSS
Published Sep 9, 2026
·Updated
zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG file upload through the /equipmentFile/upload endpoint.
Affected Software
1 affected component
zhitan EMS=1.0.0
Event History
Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments should be considered exposed?
Deployments running zhitan-ems 1.0.0 should be assessed if the /equipmentFile/upload endpoint is available and accepts SVG uploads.
2
What capability would an attacker need to exploit this issue?
The attacker needs to be able to upload an SVG file through the /equipmentFile/upload endpoint.