Cross-Site Scripting Flaw in E-Commerce Pack by Softtr Informatics Technology
CVE-2026-5218

4.3MEDIUM

What is CVE-2026-5218?

A vulnerability has been identified in the E-Commerce Pack by Softtr Informatics Technology that allows for Cross-Site Scripting (XSS). This arises from improper handling of Script-Related HTML tags in web pages, potentially enabling attackers to inject malicious scripts into web applications. End-users may unknowingly execute harmful scripts, leading to data theft and compromised security. The affected versions prior to 5.03.01.49 are at risk.

Affected Version(s)

E-Commerce Pack 0 < 5.03.01.49

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner KISA
.