Two stored XSS vulnerabilities have been disclosed in the NethServer WebTop 
module, affecting versions 1.5.6 and earlier.
CVE-2026-78331 (CVSS 4.0: 8.7) affects the calendar component, while 
CVE-2026-78332 (CVSS 4.0: 8.2) affects the contacts component.


Both vulnerabilities allow malicious content to be stored and JavaScript code 
to be executed when the affected calendar event or contact is viewed by another 
user.

Affected versions:
WebTop <= 1.5.6

Fixed version:
WebTop 1.5.7


Credits:
Vulnerability discovered by Andrea Intilangelo


References:

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-nethserver
https://github.com/NethServer/ns8-webtop/security/advisories/GHSA-cqcv-5f3w-wpmr
https://github.com/NethServer/ns8-webtop/security/advisories/GHSA-7vf9-f3rc-vg3x

Reply via email to