Executive brief
Inrove BiEticaret, an e-commerce platform, contains a security flaw that allows attackers to inject malicious scripts into the web pages viewed by users. If a user clicks a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. This issue has been addressed in version 3.3.57.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Inrove Software and Internet Services BiEticaret before version 3.3.57. The application fails to properly neutralize user-supplied input before including it in dynamically generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in the theft of sensitive information like session cookies or the performance of unauthorized actions. The vulnerability is resolved in version 3.3.57.
Affected products
- Inrove Software and Internet Services BiEticaret before v3.3.57
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory