TPVEnlanube 中存在存储型跨站脚本漏洞(XSS),影响以下端点和参数: CVE-2026-7172:端点 中的参数 'Nombre Completo'(全名)。 成功利用此漏洞可使经过身份验证的攻击者注入恶意代码,并在未经用户同意的情况下在用户浏览器中执行该代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TPVEnlanube | Cloud Web application | Actual Web Version | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7170 | 4.8 MEDIUM | Stored Cross-Site Scripting (XSS) in TPVEnlanube |
| CVE-2026-7171 | 4.8 MEDIUM | Stored Cross-Site Scripting (XSS) in TPVEnlanube |
No comments yet