PT-2026-21274 · Unknown · Svx Portal

Philopentest

·

Publicado

2026-02-20

·

Atualizado

2026-02-20

·

CVE-2026-27505

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SVXportal versions prior to 2.5
Description The software contains a stored cross-site scripting issue in the user registration process. The index.php page submits data to the admin/user action.php endpoint. User-provided data, including the Firstname, lastname, and email fields, is saved to the backend database without proper output encoding. This data is then displayed in the administrator interface via the admin/users.php page, enabling an unauthenticated remote attacker to inject and execute arbitrary JavaScript code within an administrator’s browser.
Recommendations Update to a version later than 2.5.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27505

Produtos afetados

Svx Portal