Sceawere
Vulnerability Detail
CVE-2026-12380UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in E-Commerce Pack
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 11h ago
- Vendor
- Akıllı Ticaret Software Technologies Ltd.…
- Product
- E-Commerce Pack
- Attack Type
- CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue affects E-Commerce Pack: through 2026-10-06. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-06T14:17:44.150Z",
"pubdate": "2026-10-06T14:17:44.150Z",
"executiveSummary": "Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack is vulnerable to a Reflected Cross-Site Scripting (XSS) flaw. This vulnerability arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject malicious scripts into the victim's browser session. The vulnerability affects all versions of the E-Commerce Pack up to and including 2026-10-06. The risk is significant as it allows attackers to execute arbitrary JavaScript within the security context of the user's browser, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive session tokens. Successful exploitation requires the victim to interact with a crafted link or resource containing the malicious payload. Given the vendor's non-responsiveness, users are encouraged to implement defensive measures at the application or web server level.",
"technicalDetails": "The vulnerability is identified as a Reflected XSS flaw caused by the failure of the application to properly sanitize, encode, or validate user-provided input before reflecting it in the HTTP response body. In this context, the application processes input parameters—often delivered via GET or POST requests—and embeds them directly into the HTML document structure without adequate escaping.\nThe attack flow begins when an attacker crafts a malicious URL containing a JavaScript payload within a vulnerable parameter. The attacker then lures a target user, typically an authenticated administrator or user, to click this link. Upon execution, the application reflects the malicious input back to the user's browser as part of the rendered web page. The browser, unable to distinguish between legitimate server-supplied content and injected scripts, executes the attacker's payload.\nThis execution occurs within the context of the vulnerable domain, allowing the malicious script to access the Document Object Model (DOM), retrieve local storage or session cookies marked without the 'HttpOnly' flag, and perform unauthorized requests on behalf of the victim. Because the payload is 'reflected' rather than stored, the attack does not require persistence in the backend database but remains highly effective through social engineering tactics.\nThe affected component is the web interface of the E-Commerce Pack, which inadequately handles user input during the generation of dynamic web content. Since the vendor has not provided a patch, the risk of exploitation persists across all versions up to 2026-10-06. The vulnerability can be exploited by unauthenticated remote attackers provided they can entice a victim to visit the malicious link. The impact of successful exploitation includes, but is not limited to, the exposure of session identifiers, credential harvesting, redirection to malicious phishing sites, and defacement of the legitimate site's content from the perspective of the victim."
}