Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS.

This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Raera – Ankara Web Design and Digital Advertising Agency’s Destekz includes an improper neutralization of input during web page generation, resulting in a reflected cross‑site scripting flaw. The weakness, identified as CWE‑79, allows an attacker to embed malicious scripts that execute in a victim’s browser when the victim visits a specially crafted URL or submits a manipulated form. The description does not explicitly state the full extent of potential mischief; inferred consequences could include phishing, cookie theft, or defacement through client‑side code injection, but such uses are not confirmed in the public advisory.

Affected Systems

All installations of Raera – Ankara Web Design and Digital Advertising Agency’s Destekz up to and including the release dated 02062026 are impacted. The vendor confirmed the product is no longer supported and will not issue a patch, leaving any existing deployments vulnerable.

Risk and Exploitability

The likely attack vector is a reflected XSS payload delivered via a crafted URL or form input, inferred from the description. The EPSS score of less than 1 % and absence from CISA’s KEV catalog suggest limited exploitation observed to date. However, because no official fix is available, the risk remains persistent for users who may encounter malicious links or inputs; the threat could grow as awareness spreads.

Generated by OpenCVE AI on July 22, 2026 at 13:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy a web application firewall configured to filter common XSS payloads before they reach Destekz
  • Configure a strict Content Security Policy that disallows inline scripts and restricts script sources, and enable the X‑XSS‑Protection response header to limit script execution
  • Remove or disable the unsupported Destekz component and migrate to a supported, secure solution

Generated by OpenCVE AI on July 22, 2026 at 13:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Raera
Raera destekz
Vendors & Products Raera
Raera destekz

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS. This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title XSS in Raera's Destekz
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-06T17:29:49.531Z

Reserved: 2026-03-17T12:19:47.203Z

Link: CVE-2026-4322

cve-icon Vulnrichment

Updated: 2026-07-06T17:29:45.759Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')