CVE-2026-2678 | A3factura Web Platform 4.111.2-rev.1 on A3factura customers Name cross site scripting (EUVD-2026-8850)
A vulnerability labeled as problematic has been found in A3factura Web Platform 4.111.2-rev.1 on A3factura. The affected element is an unknown function of the file a3factura-app.wolterskluwer.es/#/incomes/customers. Executing a manipulation of the argument Name can lead to cross site scripting.
This vulnerability is registered as CVE-2026-2678. It is possible to launch the attack remotely. No exploit is available.