Executive brief
Intermark IT's WebControl CMS, a platform used for managing website content, is affected by a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could steal login session information, display fake login screens to capture credentials, or perform unauthorized actions on the user's behalf. This could lead to unauthorized access to the management system or the compromise of sensitive user data.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in Intermark IT's WebControl CMS v3.5. The flaw is located in the '/portal.do' endpoint, which fails to properly sanitize the 'urlDestino' input parameter. An unauthenticated remote attacker can exploit this by crafting a malicious URL and persuading a victim to visit it. Successful exploitation allows the execution of arbitrary JavaScript code or the injection of dynamic iframes within the context of the victim's browser session. This can be leveraged to exfiltrate session cookies, perform unauthorized actions, or conduct phishing attacks. As of the advisory date, no official patch or solution has been reported.
Affected products
- Intermark IT WebControl CMS 3.5
Timeline
- 2026-06-29: advisory: Initial advisory published by INCIBE-CERT
- 2026-06-30: disclosed: CVE published to NVD dataset