CVE-2026-3953

8.8

Gosoft Software Industry and Trade Ltd. Co. · Proticaret E-Commerce

A reflected cross-site scripting vulnerability in Gosoft Software Proticaret E-Commerce allows attackers to execute arbitrary scripts via improperly neutralized input.

Executive summary

An improper neutralization vulnerability affects Gosoft Software Proticaret E-Commerce versions 5.0.0 through 6.0.1767.1383, posing significant security risks to user sessions and application integrity.

Vulnerability

This flaw involves improper neutralization of input during web page generation, specifically leading to Reflected Cross-Site Scripting (XSS) under unauthenticated user interaction conditions.

Business impact

A successful exploit could allow malicious actors to execute arbitrary script code in the context of a victim user session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of authenticated users. The high CVSS score of 8.8 reflects the severity of potential confidentiality, integrity, and availability impacts if user interactions are successfully leveraged.

Remediation

Immediate Action: Update Proticaret E-Commerce to version 6.0.1767.1383 or later as provided by Gosoft Software.

Proactive Monitoring: Monitor web server access logs for anomalous request patterns, encoded script tags, or suspicious parameters submitted to application endpoints.

Compensating Controls: Deploy a Web Application Firewall configured with robust rules to detect and block reflected cross-site scripting attempts.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations utilizing affected versions of Proticaret E-Commerce should prioritize updating their systems to the latest vendor-supplied version to neutralize the risk of cross-site scripting attacks. Apply compensating controls such as WAF rules if immediate patching is not feasible.

More Gosoft Software Industry and Trade Ltd. Co. CVEs

Sources

Originally found and disclosed by Ferit ÖZNER, per the CVE Program record.