Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92321.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92321
Upstream
  • CVE-2026-58475
Published
2026-07-14T15:17:06Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-58475 affecting package sip 4.19.25-13
Details

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script payloads within program names submitted via HTTP requests. Attackers can exploit the lack of output encoding on rendered program names to execute arbitrary JavaScript in the browsers of any users viewing the affected page, with exploitation facilitated by the absence of a required passphrase or the default passphrase 'opendoor'.

References

Affected packages

Azure Linux:3 / sip

Package

Name
sip
Purl
pkg:rpm/azure-linux/sip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.19.25-13

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92321.json"