Junglewise Threat Intelligence

CVE-2025-6397: Ankara Hosting Website Design Website Software Reflected XSS

CVE-2025-6397 · Severity: high · CVSS 8.6 · Published 2026-02-03

Executive brief

Ankara Hosting Website Design's website software contains a security flaw that allows for reflected cross-site scripting (XSS). This software is used to build and manage business websites. If exploited, an attacker could execute malicious scripts in a user's browser, potentially leading to unauthorized access to user sessions, theft of sensitive information, or disruption of the website's functionality.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Ankara Hosting Website Design Website Software through version 03022026. The flaw stems from the application's failure to properly neutralize user-supplied input before including it in generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. While the CVSS vector provided by the reporting CNA (TR-CERT) indicates a high impact on availability, XSS typically targets confidentiality and integrity through session hijacking or credential theft. The vendor has reportedly not responded to disclosure attempts.

Affected products

  • Ankara Hosting Website Design Website Software through 03022026

Timeline

  • 2026-02-03: disclosed
  • 2026-02-03: advisory: First published by TR-CERT/USOM

References