PT-2026-53834 · Unknown · Webcontrol Cms

Erik Villegas

·

Published

2026-06-30

·

Updated

2026-06-30

·

CVE-2026-6954

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions WebControl CMS version 3.5
Description An issue exists that allows an attacker to execute JavaScript code or inject a dynamic iframe into a victim's browser. This is achieved by sending a malicious URL through the urlDestino parameter in the '/portal.do' endpoint. This flaw can be used to steal sensitive user data, such as session cookies, display phishing interfaces, or perform actions on behalf of the user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the urlDestino parameter in the '/portal.do' endpoint until the issue is resolved.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6954

Affected Products

Webcontrol Cms