Impact
Entradium, a ticketing application by Crocantickets, has a stored cross‑site scripting flaw that permits arbitrary JavaScript injection into the Name and Field parameters of the /tools/discount_wizard/discount_config endpoint. The injected code is executed whenever the discount list page for an event is rendered, allowing an attacker to run scripts in the victim’s browser. Successful exploitation can lead to theft of session data and other client‑side information, effectively enabling session hijacking.
Affected Systems
The vulnerability affects all instances of Crocantickets Entradium prior to the release dates of patches 20260409151659 and 20260409153543. Admins should verify whether their deployed version predates either of these builds.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. Because a specially crafted URL can be sent to a targeted user and the payload executes in their context when they view the discount list page, the attack vector is remote and web‑based. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation is currently unclear, but the potential for compromising user sessions remains significant.
OpenCVE Enrichment