Executive brief
Mediküm Web, a web application developed by Webbeyaz Web Design, contains a security flaw that allows attackers to inject malicious scripts into the website. If a user views a page containing this malicious content, the attacker could potentially steal session information or perform unauthorized actions on the user's behalf. The vendor has stated that this product is no longer supported, meaning no official security updates will be released.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in Webbeyaz Web Design Mediküm Web through version 08072026. The root cause is the improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious scripts into the application's database, which are then executed in the browser of any user who views the affected page. The attack requires network connectivity and minimal user interaction. The vendor has confirmed the product is End-of-Life (EOL) and no patch is expected.
Affected products
- Webbeyaz Web Design Mediküm Web through 08072026
Timeline
- 2026-07-08: advisory: Advisory published by TR-CERT and NVD
- 2026-07-08: other: Vendor confirmed product is no longer supported