Description
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for setting delivery address with a malicious script, what causes the script to run in user's context. This vulnerability has been patched in version 79.0
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 79.0
Credits
Paweł Zdunek (Afine Team)
References
cert.pl/en/posts/2025/04/CVE-2024-10087
www.iksoris.pl/...ezerwacji-i-sprzedazy-biletow-iksoris.html