Impact
TPVEnlanube Cloud Web application suffers a stored cross‑site scripting vulnerability that allows an attacker to inject arbitrary JavaScript into the "Nombre Completo" field of the admin user list page. When any user loads that page, the malicious script runs in the context of the victim’s browser, potentially stealing authentication cookies, hijacking sessions, or defacing the site. The flaw is a classic input‑validation weakness (CWE‑79).
Affected Systems
All installations of the TPVEnlanube Cloud Web application that expose the /administrator/index.php?option=com_virtuemart&page=admin.user_list endpoint are vulnerable. No specific version numbers are listed, so the risk applies to any current or unpatched version. The administrator console is required to trigger the attack.
Risk and Exploitability
The CVSS score of 4.8 rates this issue as medium severity. The EPSS score is unavailable, so the exploit likelihood is unknown, but the lack of a KEV listing suggests no public exploits have been observed. Exploitation requires an authenticated administrator who can modify user records, making the attack vector likely limited to privileged accounts within the managed environment.
OpenCVE Enrichment