PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5783 Beyaz Computer Software Design Industry and Trade Ltd. Co. CVE debrief

CVE-2026-5783 is a reflected cross-site scripting (XSS) issue in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus affecting versions before V24.29750.1.0. Because the flaw can be triggered over the network and requires user interaction, it can still be impactful in web-facing deployments, with NVD assigning a HIGH CVSS score of 7.6.

Vendor
Beyaz Computer Software Design Industry and Trade Ltd. Co.
Product
CityPLus
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-23
Advisory published
2026-05-20
Advisory updated
2026-07-23

Who should care

CityPLus administrators, security teams, and organizations exposing CityPLus to users over the web should treat this as a priority update. End users who routinely access CityPLus in a browser may also be affected if they click crafted links or interact with malicious page content.

Technical summary

The issue is an improper neutralization of input during web page generation, classified as CWE-79 (cross-site scripting). The NVD vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H, indicating remote exploitation without privileges but with required user interaction. The affected release window is CityPLus before V24.29750.1.0.

Defensive priority

High priority for any internet-accessible CityPLus deployment, especially where users may follow links or interact with reflected request parameters.

Recommended defensive actions

  • Upgrade CityPLus to V24.29750.1.0 or later.
  • Review exposed CityPLus endpoints that reflect request data into HTML responses.
  • Warn users to avoid opening untrusted CityPLus links until remediation is complete.
  • Monitor for anomalous browser-side behavior or reports of injected content in CityPLus pages.

Evidence notes

The vulnerability description and affected version come from the official CVE/NVD record and the referenced USOM security notice. NVD lists the weakness as CWE-79 and marks the vulnerability status as Deferred. No exploit details or additional product behavior beyond the supplied sources are assumed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5783 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5783

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5783 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5783

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.