CVE-2026-7174:Entradium(由 Crocantickets 开发)中存在存储型跨站脚本(Stored XSS)漏洞。该漏洞具体存在于创建分配给活动的折扣过程中,端点 的 和 参数中。攻击者可向受影响参数注入 JavaScript 代码,当显示活动的折扣列表页面时,该代码将被执行。成功利用此漏洞后,远程攻击者可向受害者发送特制的 URL,从而窃取其会话数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Crocantickets | Entradium | versions before 20260409151659 and 20260409153543. | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7176 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
| CVE-2026-7175 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
| CVE-2026-7173 | 4.8 MEDIUM | Multiple vulnerabilities in Entradium by Crocantickets |
No comments yet