No advisories yet.
Solution
The vulnerability has been fixed by Schiocco team in version 3.7.8, released on February 2025.
Workaround
No workaround given by the vendor.
Wed, 25 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the 'search' parameter in '/supportboard/include/articles.php'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. | |
| Title | Reflected Cross Site Scripting (XSS) vulnerability in Support Board | |
| First Time appeared |
Schiocco
Schiocco support Board |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:schiocco:support_board:*:*:*:*:*:*:*:* cpe:2.3:a:schiocco:support_board:3.7.8:*:*:*:*:*:*:* |
|
| Vendors & Products |
Schiocco
Schiocco support Board |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-25T14:56:58.775Z
Reserved: 2026-03-25T13:28:15.555Z
Link: CVE-2026-4816
Updated: 2026-03-25T14:56:55.077Z
Status : Awaiting Analysis
Published: 2026-03-25T14:16:40.300
Modified: 2026-03-25T15:41:33.977
Link: CVE-2026-4816
No data.
OpenCVE Enrichment
No data.