PT-2026-28729 · Elecv2 · Elecv2
Zast.Ai
·
Publicado
2026-03-28
·
Atualizado
2026-03-29
·
CVE-2026-5015
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
elecV2 versions up to 3.8.3
Description
A flaw exists in elecV2, specifically within the Endpoint component. Manipulation of the
filename argument in a function related to the /logs file can lead to cross-site scripting. This issue is potentially exploitable remotely. The project was notified of the problem but has not yet responded. The exploit has been publicly disclosed.Recommendations
Versions prior to 3.8.4 should be updated.
Exploit
Correção
XSS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Elecv2