PT-2026-24842 · Undefined · Undefined
Zast.Ai
·
Publicado
2026-03-11
·
Atualizado
2026-03-11
·
CVE-2026-3955
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
elecV2P versions through 3.8.3
Description
A security issue exists in elecV2P that allows for code injection. The
runJSFile function within the wbjs.js file, part of the jsfile Endpoint component, is susceptible to manipulation. This manipulation can lead to remote code execution. The exploit for this issue has been publicly disclosed. The project maintainers were notified of the problem but have not yet responded.Recommendations
Versions through 3.8.3 should be updated when a fix becomes available. As a temporary workaround, consider disabling the
runJSFile() function until a patch is available.Exploit
Correção
Special Elements Injection
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined