Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS.

This issue affects BiEticaret: before v3.3.57.
Published: 2026-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can exploit an improper neutralization of user input during web page generation in Inrove Software and Internet Services’ BiEticaret, causing reflected XSS. The flaw allows malicious scripts to be executed in the victim’s browser when a crafted URL or form input is reflected by the application. Although the vulnerability does not permit arbitrary code execution on the server, the injected client‑side scripts can steal authentication cookies, hijack user sessions, or manipulate the displayed content.

Affected Systems

BiEticaret from Inrove Software and Internet Services prior to version 3.3.57 is affected. The flaw exists in the web application’s handling of free‑form input fields that are echoed back to the user without proper escaping.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious link or request that an authenticated or unauthenticated user clicks or submits, resulting in the reflected XSS payload being executed in their browser.

Generated by OpenCVE AI on July 26, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BiEticaret to version 3.3.57 or later.
  • Configure the application to properly escape or sanitize all user‑supplied data before rendering it in responses.
  • Implement a Content Security Policy that disallows inline scripts and restricts allowed script sources.

Generated by OpenCVE AI on July 26, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms
Vendors & Products Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.
Title XSS in Inrove Software's BiEticaret
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Inrove Software And Internet Services Bieticaret Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T12:39:41.345Z

Reserved: 2026-04-08T13:03:45.307Z

Link: CVE-2026-5793

cve-icon Vulnrichment

Updated: 2026-07-09T12:39:34.845Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')