Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS).

This issue affects E-Commerce Pack: before 5.03.01.49.
Published: 2026-08-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of script‑related HTML tags, classified as a basic XSS (CWE‑80). An attacker can embed malicious JavaScript into a response that is rendered by a victim's browser. This could allow the attacker to steal session cookies, deface the application, or redirect the victim to a phishing site.

Affected Systems

Softtr Informatics Technology Trading Limited Company E‑Commerce Pack, all releases prior to version 5.03.01.49. The problem exists in the product’s input handling prior to that version.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate overall severity, and the EPSS score is not available, suggesting low but uncertain exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need a victim to load a crafted page or provide malicious input that the application echoes without proper encoding, making exploitation easier in a web‑based context.

Generated by OpenCVE AI on August 27, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest version of Softtr E‑Commerce Pack (5.03.01.49 or newer).
  • Implement strict output encoding for all HTML content that incorporates user data, ensuring that script tags are escaped.
  • Deploy a Content Security Policy that restricts the execution of inline scripts and disallows loading of scripts from untrusted sources.

Generated by OpenCVE AI on August 27, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Softtr Informatics Technology Trading Limited Company
Softtr Informatics Technology Trading Limited Company e-commerce Pack
Vendors & Products Softtr Informatics Technology Trading Limited Company
Softtr Informatics Technology Trading Limited Company e-commerce Pack

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49.
Title HTML Injection in Softtr's E-Commerce Pack
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Softtr Informatics Technology Trading Limited Company E-commerce Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-27T15:04:10.478Z

Reserved: 2026-03-31T11:45:01.115Z

Link: CVE-2026-5218

cve-icon Vulnrichment

Updated: 2026-08-27T14:56:08.487Z

cve-icon NVD

Status : Deferred

Published: 2026-08-27T13:18:27.640

Modified: 2026-08-28T15:28:32.763

Link: CVE-2026-5218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:15:07Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)