CVE-2026-7173:Entradium(由 Crocantickets 开发)中存在跨站脚本(XSS)漏洞。攻击者可利用该漏洞向受害者发送一个特制的 URL,从而窃取其会话数据。 存储型 XSS:在创建或编辑分配给推广者的活动过程中,端点 中的 (城市)参数允许注入 JavaScript,该脚本将在活动的公开页面上执行。 反射型 XSS:在尝试创建或修改活动但未填写所有必填字段时,端点 中的 (描述)参数存在反射型 XSS 漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Crocantickets | Entradium | versions before 20260409151659 and 20260409153543. | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7174 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
| CVE-2026-7176 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
| CVE-2026-7175 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
No comments yet