PT-2026-6904 · Unknown · Loggro Pymes
CVE-2026-1959
·
Publicado
2026-02-07
·
Atualizado
2026-02-09
CVSS v4.0
5.1
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Loggro Pymes version 1.0.124
Description
A stored Cross-Site Scripting (XSS) issue exists in Loggro Pymes. The issue is located in the
/loggrodemo/jbrain/MaestraCuentasBancarias API endpoint, specifically through the descripción parameter. Successful exploitation could allow an attacker to inject malicious scripts that execute in the context of other users' browsers.Recommendations
Update Loggro Pymes to a version that addresses this issue. As a temporary workaround, sanitize the
descripción parameter to prevent the injection of malicious scripts.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Loggro Pymes