CVE-2026-76203

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via CSS hex escapes that reconstruct the url() function and evade the sanitizer blocklist
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 15:18

Updated : 2026-09-01 20:52


NVD link : CVE-2026-76203

Mitre link : CVE-2026-76203

CVE.ORG link : CVE-2026-76203


JSON object : View

Products Affected

No product.

CWE
CWE-180

Incorrect Behavior Order: Validate Before Canonicalize