CVE-2026-7171 TPVEnlanube 存储型 XSS 漏洞
影响已认证攻击者可注入恶意脚本并在他人浏览器执行
CVE-2026-7171 是 TPVEnlanube 组件中的存储型跨站脚本(XSS)漏洞。攻击者可在后台用户添加页面的 'Apellido 1' 参数中注入恶意脚本,脚本被持久化存储后在其他用户浏览时执行。
影响范围
受影响组件为 TPVEnlanube,具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为存储型 XSS,成因是 'Apellido 1' 参数输入未经过滤或转义即被保存并回显。攻击者通过 /administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart 端点提交含恶意脚本的内容,脚本随后在访问相关页面的用户浏览器中执行。
利用条件与风险
利用需攻击者具备已认证的后台访问权限,可窃取会话、冒充用户或执行其他浏览器端操作,实战风险中等。
修复建议
官方修复方案暂无公开信息,建议关注厂商更新;临时缓解可对输入参数进行严格过滤与输出转义,并限制后台访问权限。
Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter:
* CVE-2026-7171: parameter ‘Apellido 1’ in the endpoint ‘/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart’.
Successful exploitation of this vulnerability could allow an authenticated attacker to inject malicious code and execute it in users’ browsers without their consent.