Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vulnerability has been fixed in version 2602.0.0.
Workaround
No workaround given by the vendor.
Fri, 18 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data. The content entered is stored and displayed without being properly sanitised when another user, including administrative staff, views the affected profile. Successful exploitation could allow JavaScript code to be executed in the victim’s browser, access to information available within the session, or the performance of actions using the victim’s permissions. | |
| Title | Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 | |
| First Time appeared |
T-systems
T-systems tao |
|
| Weaknesses | CWE-613 | |
| CPEs | cpe:2.3:a:t-systems:tao:2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
T-systems
T-systems tao |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-18T10:38:25.576Z
Reserved: 2026-09-17T13:39:16.540Z
Link: CVE-2026-92976
Updated: 2026-09-18T10:38:20.267Z
Status : Received
Published: 2026-09-18T10:17:08.130
Modified: 2026-09-18T11:17:20.473
Link: CVE-2026-92976
No data.
OpenCVE Enrichment
No data.