Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS.

This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Scripting flaw caused by improper neutralization of user input during web page generation in Webbeyaz Web Design’s Mediküm Web. Because the input is not properly encoded, an attacker can insert malicious JavaScript that is reflected back to the user in the HTTP response. The injected script runs in the victim’s browser, allowing arbitrary client‑side code to execute.

Affected Systems

Webbeyaz Web Design’s Mediküm Web product, any version up to and including 08072026, is affected. The vendor has indicated the product is no longer supported, so no official patch or update is available.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity level. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to craft a request containing malicious input that is reflected in the page viewed by the victim.

Generated by OpenCVE AI on July 26, 2026 at 18:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Validate and encode all user inputs on the server side before including them in the HTML response.
  • Deploy a stricter Content‑Security‑Policy header that blocks inline scripts and restricts script sources to trusted domains.
  • Use a Web Application Firewall that can detect and block reflected XSS payloads.
  • Because the product is unsupported, consider migrating the application to a supported platform or decommissioning it.

Generated by OpenCVE AI on July 26, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Webbeyaz Website Design
Webbeyaz Website Design mediküm Web
Vendors & Products Webbeyaz Website Design
Webbeyaz Website Design mediküm Web

Wed, 08 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title Reflected XSS in Webbeyaz's Mediküm Web
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Webbeyaz Website Design Mediküm Web
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T08:54:45.184Z

Reserved: 2026-05-11T12:28:40.105Z

Link: CVE-2026-8310

cve-icon Vulnrichment

Updated: 2026-07-08T14:46:00.654Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T18:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')