Impact
The vulnerability is a stored cross‑site scripting flaw in the TPVEnlanube Cloud Web application. An authenticated administrator can insert JavaScript into the 'Apellido 1' parameter on the user creation/editing endpoint, and the code is persisted and presented to other browser users without their consent. This allows an attacker to execute arbitrary scripts in victim browsers, potentially leading to session hijacking, data theft or defacement of the web interface.
Affected Systems
The flaw is present in the TPVEnlanube Cloud Web application; no specific product version is listed. The affecting endpoint is /administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart, and the vulnerable field is named 'Apellido 1'. Administrators who deploy this application need to check whether the endpoint is active and whether the field accepts unfiltered input.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. The attack requires an authenticated session that can reach the administration interface; once authenticated, the attacker can submit malicious payloads that are stored and rendered to other users, resulting in client‑side script execution.
OpenCVE Enrichment