What is CVE-2026-47689?
CVE-2026-47689 is a vulnerability in the FOG open-source cloning and inventory management system. The `buildRow()` method in `fogpage.class.php` uses `str_replace()` without HTML escaping, allowing unauthenticated XSS attacks. Affected versions prior to 1.5.10.1832 and 1.6.0-beta.2313 should be updated immediately.
Azərbaycanca: CVE-2026-47689, FOG açıq mənbə klonlama və inventar idarəetmə sistemində aşkarlanmış zəiflikdir. `fogpage.class.php` faylındakı `buildRow()` metodu HTML-dən qaçınma (escaping) etmədən `str_replace()` istifadə etdiyi üçün, autentifikasiya olunmamış şəxs XSS hücumu həyata keçirə bilər. 1.5.10.1832 və 1.6.0-beta.2313 versiyalarından əvvəlki versiyalar təsirlənir, dərhal yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of the FOG system was CVE-2026-47689 discovered?
The vulnerability was discovered in the `buildRow()` method in the `fogpage.class.php` file.
What measure should be taken to protect against CVE-2026-47689?
Versions prior to 1.5.10.1832 and 1.6.0-beta.2313 are affected, so an immediate update is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.