Unknown · Ligerosmart · CVE-2026-2546
**Name of the Vulnerable Software and Affected Versions**
LigeroSmart versions up to 6.1.26
**Description**
A security issue exists in LigeroSmart that allows for cross site scripting. The issue is related to manipulation of the `SortBy` argument in the `/otrs/index.pl` file within an unknown function. The attack can be launched remotely. The exploit has been publicly disclosed.
**Recommendations**
Versions prior to 6.1.26 should be updated. As a temporary workaround, consider restricting or carefully validating the `SortBy` argument in the `/otrs/index.pl` file.