Stored XSS Vulnerability in E-Logo Purchasing Portal by Logo Software Industry and Trade Inc.
CVE-2026-8166

5.4MEDIUM

What is CVE-2026-8166?

The E-Logo Purchasing Portal, developed by Logo Software Industry and Trade Inc., contains a stored cross-site scripting (XSS) vulnerability. This issue arises from improper handling of user-supplied input during web page generation, allowing attackers to execute arbitrary scripts in the context of a user’s session. Users of versions prior to 1.52 are particularly at risk as they may unknowingly expose sensitive information or become victims of phishing attacks. It is crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

e-Logo Purchasing Portal 0 < 1.52

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamza Metin GERDAN
.