Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Cr0Wld3R

#42838de 53,639
6.1CVSS total
Vulnerabilidades · 1
PT-2026-29029
6.1
2026-03-30
Unknown · Ingestate Server · CVE-2026-30082
**Name of the Vulnerable Software and Affected Versions** IngEstate Server version 11.14.0 **Description** The software contains multiple stored cross-site scripting (XSS) issues within the Edit feature of the Software Package List page. These issues allow attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the `About application`, `What's news`, or `Release note` parameters. **Recommendations** Apply input validation and sanitization to the `About application`, `What's news`, and `Release note` parameters in the Edit feature of the Software Package List page.