Cross Site Scripting Vulnerability in projeto-siga Application by projeto-siga
CVE-2026-6990
Key Information:
- Vendor
Projeto-siga
- Status
- Vendor
- CVE Published:
- 25 April 2026
Badges
What is CVE-2026-6990?
A cross site scripting vulnerability exists in the projeto-siga application version 11.0.3.18, specifically in an unknown function within the file /sigawf/app/responsavel/novo. This flaw allows an attacker to manipulate parameters, particularly the Nome/Descrição arguments, to execute arbitrary scripts in the context of the user. This could lead to session hijacking, data theft, and other malicious activities. Despite being reported, the project maintainers have not yet addressed the issue, leaving users at risk for exploitation by remote attackers.
Affected Version(s)
siga 11.0.3.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
