Executive brief
A cross-site scripting (XSS) vulnerability exists in EKA Software's Real Estate Script V5, a platform used for managing real estate listings and store modules. This flaw allows attackers to inject malicious scripts into web pages viewed by other users. Successful exploitation could lead to unauthorized actions being performed in a user's session or the theft of sensitive information.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5. The flaw is caused by improper neutralization of input during web page generation within the platform's core modules, including the Doping and Store modules. An unauthenticated remote attacker can exploit this by sending specially crafted input that is subsequently rendered in a victim's browser. This can result in the execution of arbitrary JavaScript in the context of the user's session. As of the disclosure date, the vendor has not responded to reports of this vulnerability.
Affected products
- EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) through 17022026
Timeline
- 2026-02-17: advisory: Initial disclosure by USOM/TR-CERT
- 2026-02-17: disclosed: CVE published to NVD