XSS Vulnerability in Eimzamip by İzometri IT Services
CVE-2026-89290

3.5LOW

What is CVE-2026-89290?

A serious XSS vulnerability exists in the Eimzamip product from İzometri IT Services, allowing attackers to inject malicious scripts into web pages. This weakness can lead to stored XSS, putting user data at risk and compromising the integrity of the affected web application. Users running Eimzamip versions from 1.6.4 up to (but not including) 1.6.7 are encouraged to apply the necessary patches to mitigate this vulnerability.

Affected Version(s)

eimzamip v1.6.4

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Koray Danışma
Tahsin Ünlütürk
.