{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-12559", "assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84", "state": "PUBLISHED", "assignerShortName": "OpenText", "dateReserved": "2026-06-17T20:14:40.235Z", "datePublished": "2026-09-24T14:18:21.380Z", "dateUpdated": "2026-09-24T14:51:31.952Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f81092c5-7f14-476d-80dc-24857f90be84", "shortName": "OpenText", "dateUpdated": "2026-09-24T14:18:21.380Z" }, "title": "Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-79", "description": "CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-592", "descriptions": [ { "lang": "en", "value": "CAPEC-592 Stored XSS" } ] } ], "affected": [ { "vendor": "OpenText", "product": "Vendor Invoice Management for SAP Solutions", "platforms": [ "SAP Fiori" ], "modules": [ "SAP Fiori Capture Validation application" ], "versions": [ { "status": "affected", "version": "VIM 7.6/20.4", "lessThanOrEqual": "0009", "versionType": "custom" }, { "status": "affected", "version": "VIM 23.4", "lessThanOrEqual": "0004", "versionType": "custom" }, { "status": "affected", "version": "VIM 25.4", "lessThanOrEqual": "0001", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "