PT-2026-6904 · Unknown · Loggro Pymes

CVE-2026-1959

·

Publicado

2026-02-07

·

Atualizado

2026-02-09

CVSS v4.0

5.1

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Loggro Pymes version 1.0.124
Description A stored Cross-Site Scripting (XSS) issue exists in Loggro Pymes. The issue is located in the /loggrodemo/jbrain/MaestraCuentasBancarias API endpoint, specifically through the descripción parameter. Successful exploitation could allow an attacker to inject malicious scripts that execute in the context of other users' browsers.
Recommendations Update Loggro Pymes to a version that addresses this issue. As a temporary workaround, sanitize the descripción parameter to prevent the injection of malicious scripts.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1959

Produtos afetados

Loggro Pymes