CVE-2026-2677

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolterskluwer:a3factura:4.111.2:rev.1:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-26 13:16

Updated : 2026-06-17 10:31


NVD link : CVE-2026-2677

Mitre link : CVE-2026-2677

CVE.ORG link : CVE-2026-2677


JSON object : View

Products Affected

wolterskluwer

  • a3factura
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')