CVE-2024-27708

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:airc:mynet:*:*:*:*:*:*:*:*

History

02 Jan 2026, 14:28

Type Values Removed Values Added
First Time Airc mynet
Airc
References () https://github.com/esquim0/Common_Vulnerabilities_and_Exposures_CVE/blob/main/2024/MyNet.md - () https://github.com/esquim0/Common_Vulnerabilities_and_Exposures_CVE/blob/main/2024/MyNet.md - Exploit, Third Party Advisory
References () https://www.airc.pt/solucoes-servicos/solucoes?segment=MYN - () https://www.airc.pt/solucoes-servicos/solucoes?segment=MYN - Product
CPE cpe:2.3:a:airc:mynet:*:*:*:*:*:*:*:*

22 Dec 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CWE CWE-75
CWE-74

22 Dec 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 20:15

Updated : 2026-01-02 14:28


NVD link : CVE-2024-27708

Mitre link : CVE-2024-27708

CVE.ORG link : CVE-2024-27708


JSON object : View

Products Affected

airc

  • mynet
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)