{"id":"CVE-2026-7175","title":"CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;","summary":"CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-79"],"vendor":"Crocantickets","product":"Entradium","affected":["Entradium versions  before 20260409151659 and 20260409153543."],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T10:17:16.963","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7175","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-entradium-crocantickets","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-01T10:42:06.121Z","slug":"CVE-2026-7175","body":"## Overview\n\nCVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}