PT-2026-21855 · Mercator · Mercator
Hadhub
·
Publicado
2026-02-25
·
Atualizado
2026-02-27
·
CVE-2026-27639
CVSS v4.0
8.5
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mercator versions prior to 2026.02.22
Description
Mercator is a web application for mapping information systems. A stored Cross-Site Scripting (XSS) issue exists because of the use of unescaped Blade directives (
{!! !!}) in display templates. An authenticated user with the User role can inject JavaScript payloads into fields like "contact point" when creating or editing entities. This injected code executes in the browsers of users viewing the affected page, potentially including administrators. The vulnerable component uses unescaped Blade directives, which allow for the execution of arbitrary code within the application's context.Recommendations
Update to version 2026.02.22 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mercator