<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mercator on hadzah</title><link>https://hadrien.cat/tags/mercator/</link><description>Recent content in Mercator on hadzah</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 21 Feb 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hadrien.cat/tags/mercator/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-27639 Mercator — Account Takeover via Stored XSS</title><link>https://hadrien.cat/posts/mercator-account-takeover/</link><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><guid>https://hadrien.cat/posts/mercator-account-takeover/</guid><description>Description A low-privileged user (with the User role) can achieve a full administrator account takeover on Mercator by injecting a malicious script into the contact_point field when creating an entity. When an admin visits the entity listing page, the payload executes in their browser context, silently changing the admin password without any re-authentication.
Product Mercator Version &amp;lt;= 2026.03.01 Type CWE-79: Improper Neutralization of Input During Web Page Generation (&amp;lsquo;Cross-site Scripting&amp;rsquo;) CVSS 4.</description></item></channel></rss>