Description
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:

* CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.




Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Published: 2026-09-28
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Malicious code execution via XSS
Action: Monitor
AI Analysis

Impact

TPVEnlanube Cloud Web application suffers a stored cross‑site scripting vulnerability that allows an attacker to inject arbitrary JavaScript into the "Nombre Completo" field of the admin user list page. When any user loads that page, the malicious script runs in the context of the victim’s browser, potentially stealing authentication cookies, hijacking sessions, or defacing the site. The flaw is a classic input‑validation weakness (CWE‑79).

Affected Systems

All installations of the TPVEnlanube Cloud Web application that expose the /administrator/index.php?option=com_virtuemart&page=admin.user_list endpoint are vulnerable. No specific version numbers are listed, so the risk applies to any current or unpatched version. The administrator console is required to trigger the attack.

Risk and Exploitability

The CVSS score of 4.8 rates this issue as medium severity. The EPSS score is unavailable, so the exploit likelihood is unknown, but the lack of a KEV listing suggests no public exploits have been observed. Exploitation requires an authenticated administrator who can modify user records, making the attack vector likely limited to privileged accounts within the managed environment.

Generated by OpenCVE AI on September 28, 2026 at 11:53 UTC.

Remediation

Vendor Solution

There is no reported solution at this time.


OpenCVE Recommended Actions

  • Sanitize and escape all content stored in the "Nombre Completo" field before rendering; use appropriate output encoding to block script injection.
  • Restrict administrative privileges to only users who truly need to edit user data and ensure that accounts lacking this permission cannot access the vulnerable endpoint.
  • Apply any vendor‑supplied patch or update from TPVEnlanube once it becomes available; regularly check the vendor’s advisory port for fixes.
  • Deploy a Content Security Policy header that disables inline scripts or limits script sources to trusted domains as an interim mitigation.

Generated by OpenCVE AI on September 28, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users' browsers without their consent.
Title Stored Cross-Site Scripting (XSS) in TPVEnlanube
First Time appeared Tpvenlanube
Tpvenlanube cloud Web Application
Weaknesses CWE-79
CPEs cpe:2.3:a:tpvenlanube:cloud_web_application:actual_web_version:*:*:*:*:*:*:*
Vendors & Products Tpvenlanube
Tpvenlanube cloud Web Application
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Tpvenlanube Cloud Web Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-28T09:50:16.106Z

Reserved: 2026-04-27T07:49:19.454Z

Link: CVE-2026-7172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T10:16:45.763

Modified: 2026-09-28T10:16:45.763

Link: CVE-2026-7172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:59Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')