Impact
Improper neutralization of user input during web page generation creates a reflected XSS vulnerability in Dayneks Software Industry and Trade Inc.'s E‑Commerce Platform. Based on the description, it is inferred that the attacker must craft a malicious URL that a victim clicks to trigger the injection, allowing an attacker to inject arbitrary client‑side script into a victim’s browser when an engineered request is served, enabling phishing or session theft. The flaw is a classic XSS flaw, identified as CWE‑79.
Affected Systems
The affected product is Dayneks Software Industry and Trade Inc.'s E‑Commerce Platform; all released versions through 28082026 are vulnerable. No later builds are mentioned.
Risk and Exploitability
The CVSS base score is 6.1, indicating a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker must persuade a victim to click a crafted URL or otherwise submit a malicious request, enabling a reflected XSS attack. Exploitation would be typical of client‑side scripting attacks that rely on social engineering to entice the user to visit the malformed page.
OpenCVE Enrichment