PT-2026-6904 · Unknown · Loggro Pymes

CVE-2026-1959

·

Published

2026-02-07

·

Updated

2026-02-09

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Loggro Pymes version 1.0.124
Description A stored Cross-Site Scripting (XSS) issue exists in Loggro Pymes. The issue is located in the /loggrodemo/jbrain/MaestraCuentasBancarias API endpoint, specifically through the descripción parameter. Successful exploitation could allow an attacker to inject malicious scripts that execute in the context of other users' browsers.
Recommendations Update Loggro Pymes to a version that addresses this issue. As a temporary workaround, sanitize the descripción parameter to prevent the injection of malicious scripts.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1959

Affected Products

Loggro Pymes