CVE-2026-7173: Multiple vulnerabilities in Entradium by Crocantickets

Published Oct 1, 2026
·
Updated

CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data.

(Stored XSS) The City parameter in the endpoint /events/<eventname>/editgeneral during the process of creating or editing events assigned to a promoter allows for the injection of JavaScript that will execute on the event’s public page. (Reflected XSS) The Description parameter in the endpoint /events/<eventname>/edit-general when attempting to create or modify an event without filling in all required fields.

Affected Software

1 affected component
Crocantickets Entradium

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Entradium by Crocantickets to a version that resolves this vulnerability.

    Fixed in 20260409151659
  2. Upgrade

    Upgrade Entradium by Crocantickets to a version that resolves this vulnerability.

    Fixed in 20260409153543

Event History

Oct 1, 2026
CVE Published
via MITRE·09:54 AM
Data Sourced
via MITRE·09:54 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who needs to be authenticated to exploit the stored XSS issue?

The stored XSS is associated with creating or editing events assigned to a promoter, so an attacker needs promoter-level access capable of using the event editing workflow. The injected JavaScript executes on the affected event's public page.

2

What user interaction is required for exploitation?

A victim must be induced to visit a specially crafted URL for the reflected XSS scenario. For the stored XSS scenario, JavaScript executes when a user visits the public page of an event containing the malicious City value.

3

Which inputs and endpoints are affected?

The stored XSS affects the City parameter in /events/<event_name>/edit_general. The reflected XSS affects the Description parameter in /events/<event_name>/edit-general when an event is created or modified without all required fields completed.

4

What could an attacker obtain through successful exploitation?

A successful attack could allow an attacker to steal a victim's session data. The reported impact is limited to integrity effects in the vulnerable component; no confidentiality or availability impact is listed in the provided CVSS vector.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203