Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.
An attacker can inject a malicious iframe element via an unsecured 'src' parameter in the MyNET application. The vulnerability falls under the category of CWE-74 (Improper Neutralization of Special Elements) and CWE-75 (Failure to Sanitize Special Elements), which means the application does not properly filter input data passed in this parameter. The attack vector is network-based, does not require authentication, but requires user interaction (e.g., clicking on a crafted link), and the attack scope extends beyond the original application (Scope: Changed).
Successful exploitation of the vulnerability allows an attacker to execute arbitrary code in the context of the victim's browser, which may lead to complete session takeover, disclosure of sensitive data, or further attacks on the organization's infrastructure.
Patches available from the vendor should be applied in accordance with the references. It is recommended to update the MyNET application to a version newer than 26.06 and verify the correctness of the 'src' parameter filtering after the update is deployed.
Airc MyNET in version 26.06 and all earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HAirc Mynet
APPAirc≤ 26.06
Related vulnerabilities
Stwierdzono, że MyNET do wersji v26.08 zawiera podatność reflected XSS przekazaną przez parametr ficheiro.
MyNET do wersji v26.08.316 zawiera podatność SQL injection bez wymagania uwierzytelnienia przez parametr intme...
Podatność reflected cross-site scripting (XSS) w MyNET do wersji v26.08 pozwala atakującym na wykonanie dowoln...
MyNET do wersji v26.05 zawiera lukę reflected XSS w parametrze src.
MyNET do wersji v26.05 zawiera podatność reflected XSS przez parametr msg.