Impact
The vulnerability is a persistent cross‑site scripting flaw that allows unauthenticated users to embed and store malicious JavaScript snippets in the contact form fields. These scripts reside in the message database and execute when an administrator opens the message in the inbox interface. This exposure originates from improper input validation on the name, subject, and message parameters of the /gmusic/zuzconsole/___contact endpoint (CWE‑79).
Affected Systems
Affected by this flaw are installations of Zuz Music version 2.1. No other versions are known to be impacted. The vendor is Zuz, and the product is the Zuz Music platform.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only the ability to submit a crafted contact request; it does not need admin credentials to inject the payload, but the effect materializes only after an administrator views the message. Consequently, the risk is moderate and primarily concerns admins who routinely access the inbox.
OpenCVE Enrichment