Description
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:

* CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'.


Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Published: 2026-09-28
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site XSS affecting client browsers
Action: Mitigate
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the TPVEnlanube Cloud Web application. An authenticated administrator can insert JavaScript into the 'Apellido 1' parameter on the user creation/editing endpoint, and the code is persisted and presented to other browser users without their consent. This allows an attacker to execute arbitrary scripts in victim browsers, potentially leading to session hijacking, data theft or defacement of the web interface.

Affected Systems

The flaw is present in the TPVEnlanube Cloud Web application; no specific product version is listed. The affecting endpoint is /administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart, and the vulnerable field is named 'Apellido 1'. Administrators who deploy this application need to check whether the endpoint is active and whether the field accepts unfiltered input.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. The attack requires an authenticated session that can reach the administration interface; once authenticated, the attacker can submit malicious payloads that are stored and rendered to other users, resulting in client‑side script execution.

Generated by OpenCVE AI on September 28, 2026 at 12:53 UTC.

Remediation

Vendor Solution

There is no reported solution at this time.


OpenCVE Recommended Actions

  • Check the TPVEnlanube vendor website or support channels for any available patches or updates that address this vulnerability.
  • Restrict access to the /administrator endpoint so that only trusted administrators can submit user data.
  • Implement strict input validation and output encoding for the 'Apellido 1' field to prevent script injection.
  • Deploy a web application firewall or XSS filtering mechanism to detect and block malicious JavaScript payloads.
  • Monitor application logs for unexpected input in the 'Apellido 1' parameter and other administrative actions.

Generated by OpenCVE AI on September 28, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Title Stored Cross-Site Scripting (XSS) in TPVEnlanube
First Time appeared Tpvenlanube
Tpvenlanube cloud Web Application
Weaknesses CWE-79
CPEs cpe:2.3:a:tpvenlanube:cloud_web_application:actual_web_version:*:*:*:*:*:*:*
Vendors & Products Tpvenlanube
Tpvenlanube cloud Web Application
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Tpvenlanube Cloud Web Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-28T09:50:18.326Z

Reserved: 2026-04-27T07:49:17.656Z

Link: CVE-2026-7171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T10:16:45.637

Modified: 2026-09-28T10:16:45.637

Link: CVE-2026-7171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:56Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')