CVE-2026-6743 Details
Description
A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A cross-site scripting (XSS) vulnerability has been identified in WebSystems WebTOTUM version 2026. This issue affects the Calendar component, where an unknown function can be manipulated to inject web scripts or arbitrary HTML. The injected payload is stored on the server and executed in the context of other users' browsers when they access the affected page. This vulnerability arises from inadequate validation or escaping of user-supplied input, potentially allowing attackers to compromise user sessions or perform unauthorized actions. The vulnerability can be exploited remotely and requires user interaction.
Users are advised to upgrade to the latest version of WebSystems WebTOTUM. The fixed version is available for download on the WebSystems website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 21, 2026CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://olografix.org/acme/WebTOTUM-POC.gif | [email protected] | Exploit |
| https://vuldb.com/submit/794617 | [email protected] | Technical Description |
| https://vuldb.com/vuln/358434 | [email protected] | AdvisoryExploitRemedyVendor |
| https://vuldb.com/vuln/358434/cti | [email protected] | AdvisoryPermission Required |
| https://www.websys.eu/gestionale-online-in-cloud-per-pmi-callcenter | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WebSystems WebTOTUM | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 21, 2026 | New CVE Received | [email protected] |
Volerion