A vulnerability has been found in maalfer Pentestify up to 1.0.x and classified as problematic. Affected is the function
renderPreview/renderEditor/renderAuditData of the file js/app.js of the component Rendering. The manipulation of the argument images/client_logo leads to cross site scripting.
This vulnerability is documented as CVE-2026-59238. The attack can be initiated remotely. There is not any exploit available.