CVE-2026-1493
Cross-Site Scripting in LEX Baza Dokumentów
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript in the context of the victim's browser. An attacker with ability to set a cookie can perform a more severe attack, so we evaluate the impact and risk of exploitation as minimal. However, the vendor considered this a vulnerability and released a security patch. This issue was fixed in version 1.3.4.
| CWE | CWE-79 |
| Vendor | wolters kluwer polska |
| Product | lex baza dokumentów |
| Published | Apr 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for wolters kluwer polska lex baza dokumentów
Be the first to know when new unknown vulnerabilities affecting wolters kluwer polska lex baza dokumentów are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Wolters Kluwer Polska / LEX Baza Dokumentów
0 < 1.3.4
References
Credits
Marek Figielski (Vanilla.pl)