PT-2026-21450 · Unknown · Rymcu Forest

Xcxr

·

Publicado

2026-02-22

·

Atualizado

2026-02-23

·

CVE-2026-2947

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions rymcu forest versions up to 0.0.5
Description A cross-site scripting issue exists in rymcu forest. The issue is located in the updateUserInfo function within the src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java file of the User Profile Handler component. This allows for remote execution of attacks. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions prior to 0.0.5 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2947

Produtos afetados

Rymcu Forest