CRITICAL🇵🇱 Wersja polska

CVE-2024-27708

CVSS 9.6v3.1pub. 2025-12-22upd. 2026-01-02

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

🤖 AI Analysis
How it works

An attacker can inject a malicious iframe element via an unsecured 'src' parameter in the MyNET application. The vulnerability falls under the category of CWE-74 (Improper Neutralization of Special Elements) and CWE-75 (Failure to Sanitize Special Elements), which means the application does not properly filter input data passed in this parameter. The attack vector is network-based, does not require authentication, but requires user interaction (e.g., clicking on a crafted link), and the attack scope extends beyond the original application (Scope: Changed).

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary code in the context of the victim's browser, which may lead to complete session takeover, disclosure of sensitive data, or further attacks on the organization's infrastructure.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. It is recommended to update the MyNET application to a version newer than 26.06 and verify the correctness of the 'src' parameter filtering after the update is deployed.

Who is affected

Airc MyNET in version 26.06 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Airc Mynet

    APP
    Airc
    ≤ 26.06
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-35322MEDIUM6.1same product

Stwierdzono, że MyNET do wersji v26.08 zawiera podatność reflected XSS przekazaną przez parametr ficheiro.

CVE-2024-39037MEDIUM6.5same product

MyNET do wersji v26.08.316 zawiera podatność SQL injection bez wymagania uwierzytelnienia przez parametr intme...

CVE-2024-40317MEDIUM6.1same product

Podatność reflected cross-site scripting (XSS) w MyNET do wersji v26.08 pozwala atakującym na wykonanie dowoln...

CVE-2024-25812MEDIUM6.1same product

MyNET do wersji v26.05 zawiera lukę reflected XSS w parametrze src.

CVE-2024-25814MEDIUM6.1same product

MyNET do wersji v26.05 zawiera podatność reflected XSS przez parametr msg.