PT-2026-78456 · Maalfer · Pentestify

·

CVE-2026-76203

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions maalfer Pentestify versions 1.2.0 through 2.3.2
Description The report theme CSS sanitizer contains an incorrect behavior order where validation occurs before canonicalization. This allows an authenticated user to bypass the sanitizer blocklist using CSS hex escapes to reconstruct the url() function. Consequently, this can be used to force outbound HTTP requests from the browsers of other users, leading to the disclosure of their IP addresses and User-Agent strings.
Recommendations Update maalfer Pentestify to a version later than 2.3.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76203

Affected Products

Pentestify