PT-2026-6904 · Unknown · Loggro Pymes
Published
2026-02-07
·
Updated
2026-02-09
·
CVE-2026-1959
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Loggro Pymes version 1.0.124
Description
A stored Cross-Site Scripting (XSS) issue exists in Loggro Pymes. The issue is located in the
/loggrodemo/jbrain/MaestraCuentasBancarias API endpoint, specifically through the descripción parameter. Successful exploitation could allow an attacker to inject malicious scripts that execute in the context of other users' browsers.Recommendations
Update Loggro Pymes to a version that addresses this issue. As a temporary workaround, sanitize the
descripción parameter to prevent the injection of malicious scripts.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loggro Pymes