Sceawere

Vulnerability Detail

CVE-2026-5782UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TurkHotspot Reflected XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.2
Creation Date
8h ago
Vendor
Loglama.net
Product
TurkHotspot
Attack Type
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Loglama.net TurkHotspot allows Reflected XSS. This issue affects TurkHotspot: through 2026-10-02. NOTE: The vendor was contacted and it was learned that the product is not supported.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.2",
  "pubDate": "2026-10-02T15:17:10.180Z",
  "pubdate": "2026-10-02T15:17:10.180Z",
  "executiveSummary": "A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Loglama.net TurkHotspot, affecting versions up to 2026-10-02. This security flaw stems from the application's failure to properly neutralize user-controlled input during dynamic web page generation.\nAn attacker can exploit this vulnerability by distributing malicious links to users of the TurkHotspot system. If a user visits the link, the embedded malicious script executes within the context of their browser session.\nThe successful exploitation of this vulnerability can lead to session hijacking, unauthorized data access, and administrative account takeover. Since the vendor has confirmed the product is unsupported, no official patch is planned, posing a continuous security risk.",
  "technicalDetails": "The root cause of the vulnerability is the improper implementation of input validation and context-aware output encoding (CWE-79) within the TurkHotspot web interface. When parameters from HTTP requests are reflected back to the client, the application fails to sanitize characters such as angle brackets, quotes, and ampersands.\nThe attack flow begins when an adversary identifies a vulnerable parameter that is directly reflected in the server response. The attacker crafts a specific URL containing a malicious JavaScript payload designed to execute arbitrary commands in the victim's browser.\nWhen the target clicks the link, the TurkHotspot application processes the request and returns the payload in the HTML response. The victim's browser interprets the injected script as trusted code from the host origin, executing it immediately.\nPost-exploitation capabilities include accessing sensitive session identifiers, capturing keystrokes, modifying the DOM structure of the portal, or redirecting the user to external malicious domains. The vulnerability requires no prior authentication and can be executed remotely via network access to the TurkHotspot web interface."
}
CVE-2026-5782: TurkHotspot Reflected XSS Vulnerability (MEDIUM Severity, CVSS: 5.2) | Sceawere