A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/LigeroSmart/ligerosmart/ | Product |
| https://github.com/LigeroSmart/ligerosmart/issues/280 | Exploit Issue Tracking |
| https://github.com/LigeroSmart/ligerosmart/issues/280#issue-3776580352 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.341601 | Permissions Required VDB Entry |
| https://vuldb.com/?id.341601 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.729402 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.746919 | Third Party Advisory VDB Entry |
Configurations
History
27 Feb 2026, 03:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/LigeroSmart/ligerosmart/ - Product | |
| References | () https://github.com/LigeroSmart/ligerosmart/issues/280 - Exploit, Issue Tracking | |
| References | () https://github.com/LigeroSmart/ligerosmart/issues/280#issue-3776580352 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.341601 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.341601 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.729402 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.746919 - Third Party Advisory, VDB Entry | |
| First Time |
Ligerosmart
Ligerosmart ligerosmart |
|
| CPE | cpe:2.3:a:ligerosmart:ligerosmart:*:*:*:*:*:*:*:* |
23 Feb 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
17 Jan 2026, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-17 18:15
Updated : 2026-02-27 03:51
NVD link : CVE-2026-1049
Mitre link : CVE-2026-1049
CVE.ORG link : CVE-2026-1049
JSON object : View
Products Affected
ligerosmart
- ligerosmart
