Impact
Improper neutralization of user input during web page generation allows an attacker to inject malicious scripts that are reflected immediately back to the user. This cross‑site scripting flaw can be used to hijack user sessions, steal credentials, or deliver phishing payloads, all without persisting data on the server side. The weakness corresponds to CWE‑79, which highlights lack of output encoding or input filtering.
Affected Systems
The vulnerability is present in Loglama.net's TurkHotspot application through 2026‑10‑02. The vendor indicated that the product is no longer supported and does not offer a patch or update.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity; no EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker crafting a malicious URL or form value that the application echoes back without proper sanitization. Since no official fix exists, the risk remains until mitigative controls are applied or the application is replaced.
OpenCVE Enrichment