Vulnerability Description
HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the 'nombreApellidos', 'dirección ', and 'comentarios ' parameters to '/processContact.do'.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-6953?
CVE-2026-6953 is a documented vulnerability. HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit t...
How severe is CVE-2026-6953?
CVSS scoring is not yet available for CVE-2026-6953. Check NVD for updates.
Is there a patch for CVE-2026-6953?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.