CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilities have been fixed by Crocantickets team in versions 20260409151659 y 20260409153543.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page; | |
| Title | Multiple vulnerabilities in Entradium by Crocantickets | |
| First Time appeared |
Crocantickets
Crocantickets entradium |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:crocantickets:entradium:versions_before_20260409151659_and_20260409153543.:*:*:*:*:*:*:* | |
| Vendors & Products |
Crocantickets
Crocantickets entradium |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-10-01T09:56:41.977Z
Reserved: 2026-04-27T07:58:54.274Z
Link: CVE-2026-7175
No data.
Status : Deferred
Published: 2026-10-01T10:17:16.963
Modified: 2026-10-01T13:04:49.340
Link: CVE-2026-7175
No data.
OpenCVE Enrichment
Updated: 2026-10-01T11:30:05Z
Weaknesses