Impact
This vulnerability consists of a cross‑site scripting flaw in Entradium, a ticketing application from Crocantickets. Attackers can inject malicious JavaScript through the City field when creating or editing events and through the Description field during event creation or modification when not all fields are filled. The injected code will run in the context of users who view the event’s public page, allowing the attacker to steal session cookies, deface content, or perform other client‑side attacks.
Affected Systems
Affected versions are all releases of Entradium before 20260409151659 and 20260409153543, as identified by the vendor. The vulnerability is present in the /events/<event_name>/edit_general and /events/<event_name>/edit-general endpoints used by promoter‑assigned events. Only the Crocantickets:Entradium product is impacted; no other vendors or products are listed.
Risk and Exploitability
The CVSS score is 4.8, indicating a moderate impact. The EPSS score is not available and the vulnerability is not included in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. Based on the description, it is inferred that the attack vector requires an attacker to supply a crafted URL or malicious input and a victim to visit the affected event page; no prior authentication is necessary. Given the client‑side nature of the flaw, exploitation relies on victim interaction, but the potential for session hijacking remains a concern.
OpenCVE Enrichment