CVE-2026-2677

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wolterskluwer:a3factura:4.111.2:rev.1:*:*:*:*:*:*

History

02 Mar 2026, 17:15

Type Values Removed Values Added
CPE cpe:2.3:a:wolterskluwer:a3factura:4.111.2:rev.1:*:*:*:*:*:*
First Time Wolterskluwer a3factura
Wolterskluwer
Summary
  • (es) Cross-Site Scripting Reflejado (XSS) en la plataforma web A3factura, en el parámetro 'name', en el endpoint 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management', lo que podría permitir a un atacante ejecutar código arbitrario en el navegador de la víctima.
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-a3factura-software - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-a3factura-software - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

26 Feb 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 13:16

Updated : 2026-03-02 17:15


NVD link : CVE-2026-2677

Mitre link : CVE-2026-2677

CVE.ORG link : CVE-2026-2677


JSON object : View

Products Affected

wolterskluwer

  • a3factura
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')