Executive brief
Webbeyaz Mediküm Web, a web-based platform, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the pages viewed by other users. If a user clicks on a specially crafted link, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user. The vendor has stated that this product is no longer supported, meaning no official security updates will be released.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Webbeyaz Web Design Mediküm Web through version 08072026. The flaw stems from the application's failure to properly sanitize user-supplied input before including it in dynamically generated web pages (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into visiting a malicious URL containing a crafted payload. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The vendor has confirmed the product is end-of-life (EOL) and no patch is expected.
Affected products
- Webbeyaz Web Design Mediküm Web through 08072026
Timeline
- 2026-07-08: advisory: Initial disclosure by TR-CERT and NVD
- 2026-07-08: other: Vendor confirmed product is no longer supported