Impact
The vulnerability exists in the Business Name field of the /promoters/edit endpoint. Malicious JavaScript can be stored in that field and later executed when the promoter’s public profile page is viewed. This allows the attacker to run arbitrary code in the browser of anyone who visits the page, enabling cookie theft, session hijacking or defacement. It is a classic reflected XSS flaw (CWE‑79) and does not allow direct remote code execution on the server.
Affected Systems
Crocantickets Entradium, versions released before 20260409151659 and before 20260409153543 are vulnerable. These are the pre‑patch releases.
Risk and Exploitability
The CVSS score of 4.8 classifies it as low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user who can edit a promoter profile, and the attacker must then persuade visitors to load the public page for the payload to be executed. Given these constraints, exploitation probability is limited but still plausible for targeted accounts.
OpenCVE Enrichment