PT-2026-21855 · Mercator · Mercator

Hadhub

·

Publicado

2026-02-25

·

Atualizado

2026-02-27

·

CVE-2026-27639

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mercator versions prior to 2026.02.22
Description Mercator is a web application for mapping information systems. A stored Cross-Site Scripting (XSS) issue exists because of the use of unescaped Blade directives ({!! !!}) in display templates. An authenticated user with the User role can inject JavaScript payloads into fields like "contact point" when creating or editing entities. This injected code executes in the browsers of users viewing the affected page, potentially including administrators. The vulnerable component uses unescaped Blade directives, which allow for the execution of arbitrary code within the application's context.
Recommendations Update to version 2026.02.22 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27639
GHSA-65P7-PPH2-966G

Produtos afetados

Mercator