CVE-2026-7298: Reflected XSS in IdeaSoft's Smart E-Commerce
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS.
This issue affects Smart E-Commerce: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed over the network with low attack complexity and no attacker privileges. A victim must interact with attacker-controlled content or a crafted request, as indicated by the required user interaction.
What is the potential impact if exploitation succeeds?
The listed impact includes low confidentiality and integrity effects, with no availability impact. The scope is changed, meaning the impact can extend beyond the vulnerable component's original security authority.
Which Smart E-Commerce versions are affected?
The advisory states that Smart E-Commerce is affected through version 11092026. No unaffected or fixed version is provided in the available data.
Is a vendor fix or workaround available?
The available information does not provide a fix, mitigation, or workaround. It also states that the vendor was contacted early about the disclosure but did not respond.