CVE-2026-2679 | A3factura Web Platform 4.111.2-rev.1 salesInvoices customerName cross site scripting (EUVD-2026-8851)
A vulnerability marked as problematic has been reported in A3factura Web Platform 4.111.2-rev.1. The impacted element is an unknown function of the file a3factura-app.wolterskluwer.es/#/incomes/salesInvoices. The manipulation of the argument customerName leads to cross site scripting.
This vulnerability is documented as CVE-2026-2679. The attack can be initiated remotely. There is not any exploit available.