Impact
Raera – Ankara Web Design and Digital Advertising Agency’s Destekz includes an improper neutralization of input during web page generation, resulting in a reflected cross‑site scripting flaw. The weakness, identified as CWE‑79, allows an attacker to embed malicious scripts that execute in a victim’s browser when the victim visits a specially crafted URL or submits a manipulated form. The description does not explicitly state the full extent of potential mischief; inferred consequences could include phishing, cookie theft, or defacement through client‑side code injection, but such uses are not confirmed in the public advisory.
Affected Systems
All installations of Raera – Ankara Web Design and Digital Advertising Agency’s Destekz up to and including the release dated 02062026 are impacted. The vendor confirmed the product is no longer supported and will not issue a patch, leaving any existing deployments vulnerable.
Risk and Exploitability
The likely attack vector is a reflected XSS payload delivered via a crafted URL or form input, inferred from the description. The EPSS score of less than 1 % and absence from CISA’s KEV catalog suggest limited exploitation observed to date. However, because no official fix is available, the risk remains persistent for users who may encounter malicious links or inputs; the threat could grow as awareness spreads.
OpenCVE Enrichment