DOM XSS Patched in LEX Baza Dokumentów
A DOM-based XSS flaw in LEX Baza Dokumentów's cookie handling was patched in version 1.3.4 after coordinated disclosure via CERT Polska.
CERT Polska coordinated disclosure of CVE-2026-1493, a DOM-based cross-site scripting vulnerability in LEX Baza Dokumentów software. The flaw stems from unsafe client-side processing of the "em" cookie parameter, allowing an attacker capable of setting the cookie to execute arbitrary JavaScript within the victim's browser context.
CERT Polska notes that exploitation requires an attacker to already have the ability to set a cookie on the victim's browser, a precondition that would typically enable more severe attacks anyway. As a result, the practical risk and exploitation likelihood are assessed as minimal despite the vendor treating it as a legitimate vulnerability. The issue was responsibly reported by Marek Figielski of Vanilla.pl and has been fixed by the vendor in version 1.3.4.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-1493
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free