← Voltar para CVEs
CVE-2026-27639
MEDIUM5.4
Descricao
Mercator is an open source web application designed to enable mapping of information systems. A stored Cross-Site Scripting (XSS) vulnerability exists in Mercator prior to version 2026.02.22 due to the use of unescaped Blade directives (`{!! !!}`) in display templates. An authenticated user with the User role can inject arbitrary JavaScript payloads into fields such as "contact point" when creating or editing entities. The payload is then executed in the browser of any user who views the affected page, including administrators. Version 2026.02.22 fixes the vulnerability.
Detalhes CVE
Pontuacao CVSS v3.15.4
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioREQUIRED
Publicado2/25/2026
Ultima modificacao2/27/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
sourcentis:mercator
Fraquezas (CWE)
CWE-79
Referencias
https://github.com/dbarzin/mercator/commit/839d231399944e43a865198262e96e0218252cc3(security-advisories@github.com)
https://github.com/dbarzin/mercator/commit/9902ffd91f287e474729f514c77261f4ef7db8fe(security-advisories@github.com)
https://github.com/dbarzin/mercator/commit/c58bb1d2fff18605c61d93cfaf77adca416c560a(security-advisories@github.com)
https://github.com/dbarzin/mercator/security/advisories/GHSA-65p7-pph2-966g(security-advisories@github.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.