Junglewise Threat Intelligence

CVE-2026-7298: IdeaSoft Smart E-Commerce reflected cross-site scripting

CVE-2026-7298 · Severity: medium · CVSS 6.1 · Published 2026-09-11

Executive brief

IdeaSoft Smart E-Commerce is an online store platform used by businesses to sell products and manage transactions. A reflected cross-site scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by customers, potentially stealing login credentials, payment information, or hijacking user sessions. The vulnerability affects versions before 8.4.2.0 and requires user interaction to exploit.

Technical details

The vulnerability is an improper neutralization of user input in web page generation, allowing reflected XSS attacks. An attacker can craft a malicious URL that, when visited by a user, executes arbitrary JavaScript in the victim's browser within the context of the Smart E-Commerce application. This requires social engineering to trick a user into clicking the link, but does not require authentication or special network conditions.

Affected products

  • IdeaSoft Smart E-Commerce before 8.4.2.0

Timeline

  • 2026-09-11: disclosed: Vulnerability published by NVD

References