Impact
An attacker can exploit an improper neutralization of user input during web page generation in Inrove Software and Internet Services’ BiEticaret, causing reflected XSS. The flaw allows malicious scripts to be executed in the victim’s browser when a crafted URL or form input is reflected by the application. Although the vulnerability does not permit arbitrary code execution on the server, the injected client‑side scripts can steal authentication cookies, hijack user sessions, or manipulate the displayed content.
Affected Systems
BiEticaret from Inrove Software and Internet Services prior to version 3.3.57 is affected. The flaw exists in the web application’s handling of free‑form input fields that are echoed back to the user without proper escaping.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a malicious link or request that an authenticated or unauthenticated user clicks or submits, resulting in the reflected XSS payload being executed in their browser.
OpenCVE Enrichment