PT-2026-2166 · Voltronic Power+1 · Snmp Web Pro+1
Jean-Marie Bourbon
+2
·
Publicado
2026-01-09
·
Atualizado
2026-04-22
·
CVE-2026-22192
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
The software contains a stored cross-site scripting issue that permits authenticated attackers to inject malicious JavaScript. This is achieved by importing a specially crafted options file containing unescaped custom CSS field values. Attackers can provide a malicious JSON import file with script payloads within the
customCss parameter. These payloads execute on every page when rendered through the options handler due to insufficient sanitization.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Exploit
Correção
XSS
Missing Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Snmp Web Pro
Wpdiscuz