Description
CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.

* (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page.
* (Reflected XSS) The Description parameter in the endpoint /events/<event_name>/edit-general when attempting to create or modify an event without filling in all required fields.
Published: 2026-10-01
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting that can lead to session hijacking and defacement, with potentially moderate severity
Action: Patch Now
AI Analysis

Impact

This vulnerability consists of a cross‑site scripting flaw in Entradium, a ticketing application from Crocantickets. Attackers can inject malicious JavaScript through the City field when creating or editing events and through the Description field during event creation or modification when not all fields are filled. The injected code will run in the context of users who view the event’s public page, allowing the attacker to steal session cookies, deface content, or perform other client‑side attacks.

Affected Systems

Affected versions are all releases of Entradium before 20260409151659 and 20260409153543, as identified by the vendor. The vulnerability is present in the /events/<event_name>/edit_general and /events/<event_name>/edit-general endpoints used by promoter‑assigned events. Only the Crocantickets:Entradium product is impacted; no other vendors or products are listed.

Risk and Exploitability

The CVSS score is 4.8, indicating a moderate impact. The EPSS score is not available and the vulnerability is not included in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. Based on the description, it is inferred that the attack vector requires an attacker to supply a crafted URL or malicious input and a victim to visit the affected event page; no prior authentication is necessary. Given the client‑side nature of the flaw, exploitation relies on victim interaction, but the potential for session hijacking remains a concern.

Generated by OpenCVE AI on October 1, 2026 at 11:28 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed by Crocantickets team in versions 20260409151659 y 20260409153543.


OpenCVE Recommended Actions

  • Upgrade to Crocantickets Entradium version 20260409151659 or later, which contains the vendor fix.
  • If immediate upgrade is not feasible, configure the web server or application to encode or validate input for the City and Description parameters, ensuring that any user‑supplied data is escaped before rendering in the event page.
  • Deploy a web application firewall or similar controls to detect and block XSS payloads, and consider disabling public event view for untrusted content until a patch is applied.

Generated by OpenCVE AI on October 1, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. * (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page. * (Reflected XSS) The Description parameter in the endpoint /events/<event_name>/edit-general when attempting to create or modify an event without filling in all required fields.
Title Multiple vulnerabilities in Entradium by Crocantickets
First Time appeared Crocantickets
Crocantickets entradium
Weaknesses CWE-79
CPEs cpe:2.3:a:crocantickets:entradium:versions_before_20260409151659_and_20260409153543.:*:*:*:*:*:*:*
Vendors & Products Crocantickets
Crocantickets entradium
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Crocantickets Entradium
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-01T19:17:01.426Z

Reserved: 2026-04-27T07:58:50.050Z

Link: CVE-2026-7173

cve-icon Vulnrichment

Updated: 2026-10-01T19:16:26.515Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:16.680

Modified: 2026-10-01T20:17:30.863

Link: CVE-2026-7173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T17:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')