Boletín de pruebas Certificados

Imported from official source

Advisory

Cybersecurity Classified by Officially

Múltiples vulnerabilidades en TPVEnlanube

INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad media que afectan a TPVEnlanube, un software para la gestión de inventarios, almacenes, pedidos y proveedores. Las vulnerabilidades han sido descubiertas por David Padilla Alvarado.

A estas vulnerabilidades se les han asignado los siguientes códigos, puntuación base CVSS v4.0, vector del CVSS y el tipo de vulnerabilidad CWE de cada vulnerabilidad:

  • Desde CVE-2026-7170 hasta CVE-2026-7172: 4.8 | CVSS:4.0/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X | CWE-79
  • No hay solución reportada por el momento.

    Vulnerabilidad de tipo Cross-Site Scripting (XSS) almacenado en TPVEnlanube que afecta a los siguientes endpoints y parámetros:

  • CVE-2026-7170: parámetro 'vendor_store_name' en el endpoint '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_virtuemart&vendor_id=[ID]'.
  • CVE-2026-7171: parámetro 'Apellido 1' en el endpoint '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'.
  • CVE-2026-7172: parámetro 'Nombre Completo' en el endpoint '/administrator/index.php?option=com_virtuemart&page=admin.user_list'.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.incibe.es/node/668495

    Officially imported this from INCIBE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    INCIBE — imported from official source
    Official source
    https://www.incibe.es/rss.xml RSS
    Imported
    September 30, 2026 08:30
    Versions
    1 recorded
    Identity
    668495 at https://www.incibe.es

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.