PT-2026-24842 · Undefined · Undefined

Zast.Ai

·

Publicado

2026-03-11

·

Atualizado

2026-03-11

·

CVE-2026-3955

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions elecV2P versions through 3.8.3
Description A security issue exists in elecV2P that allows for code injection. The runJSFile function within the wbjs.js file, part of the jsfile Endpoint component, is susceptible to manipulation. This manipulation can lead to remote code execution. The exploit for this issue has been publicly disclosed. The project maintainers were notified of the problem but have not yet responded.
Recommendations Versions through 3.8.3 should be updated when a fix becomes available. As a temporary workaround, consider disabling the runJSFile() function until a patch is available.

Exploit

Correção

Special Elements Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3955

Produtos afetados

Undefined