216.73.217.22

CVE-2026-6743

· Published 21/04/2026 17:16 · Modified 22/04/2026 20:22

Labels: CVE-2026-6743 2026-04-21CVE-2026-6743CWE-79[email protected]

Essential information

Published
21/04/2026 17:16
Modified
22/04/2026 20:22
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
websystems / webtotum cpe:2.3:a:websystems:webtotum:2026:*:*:*:*:*:*:*

References