Cross-Site Scripting Vulnerability in Smart E-Commerce by IdeaSoft Software Industry
CVE-2026-7298

6.1MEDIUM

What is CVE-2026-7298?

A cross-site scripting vulnerability exists in the Smart E-Commerce platform developed by IdeaSoft Software Industry and Trade Inc. This vulnerability arises from improper handling of user input during page generation, allowing attackers to inject malicious scripts into web pages. As a result, the vulnerability can enable reflected XSS attacks, which could be exploited to steal session tokens or perform unauthorized actions on behalf of users. Despite attempts to communicate with the vendor regarding this issue, no response was received.

Affected Version(s)

Smart E-Commerce 0 <= 11092026

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner KISA
.