CVE-2026-6622 is a cross-site scripting (XSS) vulnerability affecting BichitroGan ISP Billing Software version 2025.3.20, specifically in the Customer Handler component within the customer edit function at the endpoint /?_route=customers/edit/. The vulnerability allows an attacker to inject malicious scripts through an unknown function in this component. The vulnerability has a low CVSS score of 2.4, with a network attack vector requiring high privilege levels and user interaction to execute. While the impact is limited to integrity compromise with no confidentiality or availability impact, the attack can be conducted remotely without complex technical prerequisites. Public exploit code is available for this vulnerability, and it is currently on the active Hot List for community attention, though it does not meet the criteria for inclusion in the Known Exploited Vulnerabilities catalog. The vendor was notified early but has not responded to the disclosure, leaving the vulnerability unpatched. Organizations using this software should monitor for exploitation attempts and consider implementing input validation controls or access restrictions until an official patch is released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BichitroGan | ISP Billing Software | 2025.3.20CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.