Description
CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
Published: 2026-10-01
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Client‑Side Scripting (Cross‑Site Scripting)
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in the Business Name field of the /promoters/edit endpoint. Malicious JavaScript can be stored in that field and later executed when the promoter’s public profile page is viewed. This allows the attacker to run arbitrary code in the browser of anyone who visits the page, enabling cookie theft, session hijacking or defacement. It is a classic reflected XSS flaw (CWE‑79) and does not allow direct remote code execution on the server.

Affected Systems

Crocantickets Entradium, versions released before 20260409151659 and before 20260409153543 are vulnerable. These are the pre‑patch releases.

Risk and Exploitability

The CVSS score of 4.8 classifies it as low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user who can edit a promoter profile, and the attacker must then persuade visitors to load the public page for the payload to be executed. Given these constraints, exploitation probability is limited but still plausible for targeted accounts.

Generated by OpenCVE AI on October 1, 2026 at 11:27 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed by Crocantickets team in versions 20260409151659 y 20260409153543.


OpenCVE Recommended Actions

  • Update Crocantickets Entradium to the patched release 20260409151659 or later (or 20260409153543 if available)
  • If an upgrade is not immediately possible, apply server‑side sanitization or HTML‑escaping to the Business Name input before rendering in public pages to neutralize injected JavaScript
  • Review all public profile rendering templates to ensure that no unfiltered user content is executed as script

Generated by OpenCVE AI on October 1, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
Title Multiple vulnerabilities in Entradium by Crocantickets
First Time appeared Crocantickets
Crocantickets entradium
Weaknesses CWE-79
CPEs cpe:2.3:a:crocantickets:entradium:versions_before_20260409151659_and_20260409153543.:*:*:*:*:*:*:*
Vendors & Products Crocantickets
Crocantickets entradium
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Crocantickets Entradium
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-01T19:19:38.755Z

Reserved: 2026-04-27T07:58:54.274Z

Link: CVE-2026-7175

cve-icon Vulnrichment

Updated: 2026-10-01T19:19:26.661Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T10:17:16.963

Modified: 2026-10-01T20:17:31.133

Link: CVE-2026-7175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')