VYPR

H6web

by Anapi Group

CVEs (2)

  • CVE-2025-1270CriFeb 13, 2025
    risk 0.59cvss 9.1epss 0.00

    Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an authenticated attacker to access other users' information by making a POST request and modifying the “pkrelated” parameter in the “/h6web/ha_datos_hermano.php” endpoint to refer to…

  • CVE-2025-1271MedFeb 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) in Anapi Group's h6web. This security flaw could allow an attacker to inject malicious JavaScript code into a URL. When a user accesses that URL, the injected code is executed in their browser, which can result in the theft of sensitive…