Impact
The vulnerability is a stored cross‑site scripting flaw where an authenticated user can include malicious JavaScript in the parameter when posting a comment. When other users retrieve the reply via the rpc.php endpoint, the injected script is executed in their browsers.
Affected Systems
The flaw affects the Wikidforum application version 2.20. No other versions or vendors are listed, so any deployment of this product at that version is susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity risk, and the EPSS estimate is < 1%, indicating a very low probability of exploitation. The vulnerability can be exploited by any authenticated forum user and requires no special privileges, so the primary attack vector is the web application. Because the flaw is client‑side, the impact is limited to victims who view the malicious reply, but widespread use could affect many users. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment