CVE-2026-7175 PUBLISHED

Multiple vulnerabilities in Entradium by Crocantickets

Assigner: INCIBE
Reserved: 27.04.2026 Published: 01.10.2026 Updated: 01.10.2026

CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor Crocantickets
Product Entradium
Versions Default: unaffected
  • Version versions before 20260409151659 and 20260409153543. is affected

Solutions

The vulnerabilities have been fixed by Crocantickets team in versions 20260409151659 y 20260409153543.

Credits

  • Cosme Vázquez Tomé finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS
  • CAPEC-592 Stored XSS