Impact
The vulnerability is a stored cross‑site scripting flaw where an authenticated user can include malicious JavaScript in the reply_text parameter when posting a comment. When other users retrieve the reply via the rpc.php endpoint, the injected script is executed in their browsers.
Affected Systems
The flaw affects the Wikidforum application version 2.20. No other versions or vendors are listed, so any deployment of this product at that version is susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity risk, and no EPSS estimate is available. The vulnerability can be exploited by any authenticated forum user and requires no special privileges, so the primary attack vector is the web application. Because the flaw is client‑side, the impact is limited to victims who view the malicious reply, but widespread use could affect many users. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment