CVE-2026-7175: Multiple vulnerabilities in Entradium by Crocantickets
CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the promoter’s public page;
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Entradium by Crocanticketsto a version that resolves this vulnerability.Fixed in 20260409151659 - Upgrade
Upgrade
Entradium by Crocanticketsto a version that resolves this vulnerability.Fixed in 20260409153543
Event History
Frequently Asked Questions
Who is exposed to the injected code?
The injected JavaScript executes on the affected promoter’s public page. Users who visit that public page may be exposed to the malicious code.
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low privileges and user interaction is required. The vulnerable input is the Business Name field in the /promoters/edit endpoint of a promoter profile.