PT-2026-21272 · Unknown · Svx Portal
Philopentest
·
Publicado
2026-02-20
·
Atualizado
2026-02-20
·
CVE-2026-27503
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SVXportal versions prior to 2.5
Description
SVXportal versions 2.5 and earlier are susceptible to a reflected cross-site scripting issue within the
admin/log.php component. The issue occurs due to the application embedding unsanitized data from the search query parameter directly into an HTML input value attribute. This allows an attacker to execute arbitrary JavaScript code in the browser of an authenticated administrator who views a specially crafted URL. Successful exploitation could lead to session hijacking, unauthorized administrative actions, or other browser-based compromises performed with the privileges of an administrator. The vulnerable parameter is search query.Recommendations
Versions prior to 2.5: Update to a newer version that addresses this vulnerability.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Svx Portal