PT-2026-24842 · Undefined · Undefined
Zast.Ai
·
Published
2026-03-11
·
Updated
2026-03-11
·
CVE-2026-3955
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
elecV2P versions through 3.8.3
Description
A security issue exists in elecV2P that allows for code injection. The
runJSFile function within the wbjs.js file, part of the jsfile Endpoint component, is susceptible to manipulation. This manipulation can lead to remote code execution. The exploit for this issue has been publicly disclosed. The project maintainers were notified of the problem but have not yet responded.Recommendations
Versions through 3.8.3 should be updated when a fix becomes available. As a temporary workaround, consider disabling the
runJSFile() function until a patch is available.Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined