Unknown · Ligerosmart · CVE-2026-2547
**Name of the Vulnerable Software and Affected Versions**
LigeroSmart versions up to 6.1.26
**Description**
A flaw exists in LigeroSmart that allows for cross site scripting. The issue is located in the `AgentDashboard` function within the `/otrs/index.pl` file. Manipulating the `Subaction` argument can trigger the flaw, potentially allowing for remote exploitation. The exploit is publicly available.
**Recommendations**
Versions prior to 6.1.26 should be updated. As a temporary workaround, consider restricting or disabling the `AgentDashboard` function until a patch is available.