CVE-2026-7173: Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.
(Stored XSS) The City parameter in the endpoint /events/<eventname>/editgeneral during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page. (Reflected XSS) The Description parameter in the endpoint /events/<eventname>/edit-general when attempting to create or modify an event without filling in all required fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entradium by Crocanticketsto a version that resolves this vulnerability.Fixed in 20260409151659 - Upgrade
Upgrade
Entradium by Crocanticketsto a version that resolves this vulnerability.Fixed in 20260409153543
Event History
Frequently Asked Questions
Who needs to be authenticated to exploit the stored XSS issue?
The stored XSS is associated with creating or editing events assigned to a promoter, so an attacker needs promoter-level access capable of using the event editing workflow. The injected JavaScript executes on the affected event's public page.
What user interaction is required for exploitation?
A victim must be induced to visit a specially crafted URL for the reflected XSS scenario. For the stored XSS scenario, JavaScript executes when a user visits the public page of an event containing the malicious City value.
Which inputs and endpoints are affected?
The stored XSS affects the City parameter in /events/<event_name>/edit_general. The reflected XSS affects the Description parameter in /events/<event_name>/edit-general when an event is created or modified without all required fields completed.
What could an attacker obtain through successful exploitation?
A successful attack could allow an attacker to steal a victim's session data. The reported impact is limited to integrity effects in the vulnerable component; no confidentiality or availability impact is listed in the provided CVSS vector.