CVE-2026-2679: Multiple vulnerabilities in A3factura software
Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2679?
CVE-2026-2679 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary code in users' browsers.
How do I fix CVE-2026-2679?
To fix CVE-2026-2679, update to the latest secure version of A3factura software provided by Wolters Kluwer.
What impact does CVE-2026-2679 have on users?
CVE-2026-2679 can lead to unauthorized execution of scripts in the victim's browser, compromising user data and privacy.
Is CVE-2026-2679 exploitable without authentication?
Yes, CVE-2026-2679 can be exploited without authentication, allowing an attacker to manipulate web requests easily.
What are the symptoms of an attack exploiting CVE-2026-2679?
Symptoms of an attack exploiting CVE-2026-2679 may include unexpected redirections, altered web pages, or unauthorized actions performed on behalf of the user.