Impact
The vulnerability allows an attacker to inject arbitrary JavaScript into the Help text and Title fields of ticket sale forms during creation or modification. When a user visits the public ticket purchase page for the event, the injected script executes in the user’s browser, potentially enabling session theft, defacement, or other malicious client‑side actions. This client‑side code injection falls under CWE‑79 and can compromise user confidentiality and integrity, but it does not provide direct server‑side code execution.
Affected Systems
The flaw exists in Crocantickets’ Entradium platform in all versions prior to the builds dated 20260409151659 and 20260409153543. Customers using any older Entradium release should treat the application as vulnerable until they apply the vendor’s fix.
Risk and Exploitability
The CVSS score of 4.8 reflects a moderate severity for an XSS that does not require user interaction. No EPSS data are available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is an authenticated discovery and modification of event forms by users who have administrative or event‑organizer privileges. Once the malicious code runs in an end‑user’s browser, the attacker can steal session cookies, deface the page, or redirect the user to phishing sites.
OpenCVE Enrichment