Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
No solution has been reported at this time.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 30 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' parameter in '/portal.do'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, display phishing interfaces, or perform actions on the user’s behalf. | |
| Title | Multiple vulnerabilities in Intermark IT's WebControl CMS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-06-30T13:14:14.775Z
Reserved: 2026-04-24T11:24:39.212Z
Link: CVE-2026-6954
Updated: 2026-06-30T13:14:09.034Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-30T10:30:11Z