Intermark It · Webcontrol Cms · CVE-2026-6953
**Name of the Vulnerable Software and Affected Versions**
Intermark IT WebControl CMS version 3.5
**Description**
An HTML injection issue exists in the contact form, allowing an attacker to send emails containing malicious HTML code to a victim. This is achieved by sending a request to the '/processContact.do' endpoint using the `nombreApellidos`, `dirección`, and `comentarios` parameters.
**Recommendations**
As a temporary workaround, restrict access to the '/processContact.do' endpoint or avoid using the `nombreApellidos`, `dirección`, and `comentarios` parameters until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.