CVE-2026-89290: HTML Injection in İzometri Informatics' eimzamip
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in İzometri IT Services Domestic and Foreign Trade Co. Ltd. Eimzamip allows Stored XSS.
This issue affects eimzamip: from v1.6.4 before v1.6.7.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
İzometri eimzamip versions from 1.6.4 before 1.6.7 are affected. The provided information does not identify any unaffected configuration within that version range.
What does an attacker need to exploit this issue?
The CVSS vector indicates network access, low privileges, and user interaction are required. Exploitation involves stored cross-site scripting through insufficient neutralization of script-related HTML tags.
What is the potential impact?
The issue has low confidentiality impact and no stated integrity or availability impact. A successful attack can execute stored HTML or script content in the context of a user who interacts with the affected page.