Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS.

This issue affects BiEticaret: before v3.3.57.
Published: 2026-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an improper neutralization of input during web page generation that results in reflected XSS in Inrove Software’s BiEticaret. The vulnerability allows malicious scripts to be executed in the victim’s browser when a crafted request is reflected by the application. While the issue does not enable arbitrary code execution on the server, the injected client‑side scripts could be used to steal authentication cookies, hijack sessions, or manipulate displayed content. These possible consequences are inferred from the nature of reflected XSS.

Affected Systems

BiEticaret from Inrove Software and Internet Services prior to version 3.3.57 is affected. The flaw exists in the web application’s handling of user input that is reflected without proper escaping.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the most likely attack vector is a malicious link or request that an authenticated or unauthenticated user follows or submits, leading to execution of the reflected payload in their browser.

Generated by OpenCVE AI on July 31, 2026 at 13:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade BiEticaret to version 3.3.57 or later.
  • Configure the application to properly escape or sanitize all user‑supplied data before rendering it in responses.
  • Implement a Content Security Policy that disallows inline scripts and restricts allowed script sources.

Generated by OpenCVE AI on July 31, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms
Vendors & Products Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.
Title XSS in Inrove Software's BiEticaret
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Inrove Software And Internet Services Bieticaret Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T12:39:41.345Z

Reserved: 2026-04-08T13:03:45.307Z

Link: CVE-2026-5793

cve-icon Vulnrichment

Updated: 2026-07-09T12:39:34.845Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T10:16:27.320

Modified: 2026-07-09T16:21:30.600

Link: CVE-2026-5793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')