Description
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS.

This issue affects eimzamip: from v1.6.4 before v1.6.7.
Published: 2026-10-08
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (HTML injection)
Action: Apply Patch
AI Analysis

Impact

Improper neutralization of script‑related HTML tags allows basic stored XSS. An attacker can submit malicious HTML or JavaScript that is then rendered for all users, potentially enabling credential theft, defacement, or session hijack. The vulnerability is classified as a basic XSS (CWE‑80).

Affected Systems

İzometri IT Services Domestic and Foreign Trade Co. Ltd. product eimzamip is affected. Versions from 1.6.4 through 1.6.6 (inclusive) are vulnerable; versions 1.6.7 and later contain the fix.

Risk and Exploitability

The CVSS score of 3.5 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires the ability to submit data that is stored and later rendered on a web page; no privilege escalation or remote code execution is provided.

Generated by OpenCVE AI on October 8, 2026 at 16:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade eimzamip to version 1.6.7 or later.
  • Restrict or sanitize input fields that accept user‑supplied content, ensuring all HTML is properly escaped before storage.
  • Deploy a Content Security Policy (CSP) that limits the execution of inline scripts and restricts allowable sources for scripts and styles.

Generated by OpenCVE AI on October 8, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS. This issue affects eimzamip: from v1.6.4 before v1.6.7.
Title HTML Injection in İzometri Informatics' eimzamip
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-10-08T13:57:01.956Z

Reserved: 2026-09-11T12:22:23.701Z

Link: CVE-2026-89290

cve-icon Vulnrichment

Updated: 2026-10-08T13:56:57.928Z

cve-icon NVD

Status : Received

Published: 2026-10-08T14:17:02.010

Modified: 2026-10-08T14:17:02.010

Link: CVE-2026-89290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:30:05Z

Weaknesses
  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)