PT-2026-21272 · Unknown · Svx Portal

Philopentest

·

Publicado

2026-02-20

·

Atualizado

2026-02-20

·

CVE-2026-27503

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SVXportal versions prior to 2.5
Description SVXportal versions 2.5 and earlier are susceptible to a reflected cross-site scripting issue within the admin/log.php component. The issue occurs due to the application embedding unsanitized data from the search query parameter directly into an HTML input value attribute. This allows an attacker to execute arbitrary JavaScript code in the browser of an authenticated administrator who views a specially crafted URL. Successful exploitation could lead to session hijacking, unauthorized administrative actions, or other browser-based compromises performed with the privileges of an administrator. The vulnerable parameter is search query.
Recommendations Versions prior to 2.5: Update to a newer version that addresses this vulnerability.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27503

Produtos afetados

Svx Portal