{"id":"CVE-2026-7173","title":"CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets","summary":"CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.\n\n  *  (Stored …","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-79"],"vendor":"Crocantickets","product":"Entradium","affected":["Entradium versions  before 20260409151659 and 20260409153543."],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T10:17:16.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7173","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-entradium-crocantickets","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-01T10:42:06.120Z","slug":"CVE-2026-7173","body":"## Overview\n\nCVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.\n\n  *  (Stored XSS) The City parameter in the endpoint /events/<event_name>/edit_general during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page.\n  *  (Reflected XSS) The Description parameter in the endpoint /events/<event_name>/edit-general when attempting to create or modify an event without filling in all required fields.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}