PT-2026-26213 · Avo · Avo
Timwis
·
Publicado
2026-03-18
·
Atualizado
2026-03-24
·
CVE-2026-33209
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Avo versions prior to 3.30.3
Description
A reflected cross-site scripting (XSS) issue exists in the
return to query parameter within the Avo interface. An attacker can create a malicious URL that injects arbitrary JavaScript. This JavaScript is executed when a dynamically generated navigation button is clicked. The impact of this issue varies depending on the deployment configuration, potentially allowing the execution of arbitrary JavaScript in the context of the application. In unauthenticated setups, exploitation is possible through crafted links sent to users. In authenticated setups, exploitation is limited to authenticated users and requires interaction.Recommendations
Update to Avo version 3.30.3 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Avo