PT-2026-21272 · Unknown · Svx Portal

Philopentest

·

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-27503

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SVXportal versions prior to 2.5
Description SVXportal versions 2.5 and earlier are susceptible to a reflected cross-site scripting issue within the admin/log.php component. The issue occurs due to the application embedding unsanitized data from the search query parameter directly into an HTML input value attribute. This allows an attacker to execute arbitrary JavaScript code in the browser of an authenticated administrator who views a specially crafted URL. Successful exploitation could lead to session hijacking, unauthorized administrative actions, or other browser-based compromises performed with the privileges of an administrator. The vulnerable parameter is search query.
Recommendations Versions prior to 2.5: Update to a newer version that addresses this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27503

Affected Products

Svx Portal