S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Web Vulnerabilities·Updated Sep 2, 2026

CVE-2026-57582 Scanner

CVE-2026-57582 Scanner - Cross-Site Scripting (XSS) vulnerability in GeoNetwork

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

GeoNetwork is an open-source cataloging portal use widely by geographical data administrators and geographic information systems (GIS) professionals. This platform facilitates easy access to spatial data, spatial data descriptions, and associated metadata across various repositories. GeoNetwork versions 4.4.5 through 4.4.11 allow users and administrators to search for data and manage metadata, which makes them crucial for ensuring accurate data dissemination and acquisition in geo-databases. As a widely adopted tool in geographic information science, maintaining the integrity and security of GeoNetwork installations is essential to prevent data misuse and ensure accurate geospatial information distribution. The software is frequently used by governmental agencies, international organizations, non-governmental organizations, and academic institutions worldwide.

The vulnerability under examination is a reflected cross-site scripting (XSS) flaw found in GeoNetwork versions 4.4.5 through 4.4.11, specifically in the catalog search functionality. The threat manifests when a user interacts with the service's 'uiconfig' query parameter, which is incorporated into a JavaScript context without adequate input validation or sanitization. Attackers can exploit this vulnerability by crafting and sending a malicious URL to a victim. If a victim clicks the URL, the attacker can execute arbitrary JavaScript code in the victim's browser session, potentially compromising sensitive user data.

Detailed technical analysis reveals that the vulnerable component is the 'uiconfig' query parameter used in the 'catalog.search' endpoint of GeoNetwork. This parameter is directly injected into the JavaScript context, creating an avenue for JavaScript execution with insufficient cleansing of user inputs. An attacker can easily manipulate this parameter to execute chosen scripts in the context of the affected application, targeting unsuspecting users who trigger this input processing. Potential use cases for exploitation include site defacement, data theft, or session hijacking, especially harmful if a privileged GeoNetwork user, like an administrator, is tricked into visiting the malicious link.

When exploited, this vulnerability potentially allows an attacker to execute arbitrary JavaScript in the victim's browser, leading to a wide array of potential impacts. If a privileged user, such as a GeoNetwork administrator, is targeted and their session is compromised, an attacker could escalate privileges, gain unauthorized access, modify or delete data, gain further infrastructure insights, or perform further attacks from within the network. This threat highlights the critical need for validating and sanitizing user inputs to mitigate client-side execution risks.

REFERENCES

Solution Advice
  • Upgrade GeoNetwork to version 4.4.12 or later to fix the XSS vulnerability.
  • Implement input validation and sanitization procedures to prevent future vulnerabilities.
  • Regularly conduct security audits to identify and mitigate potential threats.
  • Train administrators and users on the risk of malicious URLs and how to recognize phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.