Impact
Cute Editor for ASP.NET 6.4 contains a reflected cross‑site scripting vulnerability caused by insufficient validation of the Theme query string parameter in colorpicker_more.aspx. The flaw allows a remote attacker to construct a URL that, when visited by a victim who is logged into a site hosting the vulnerable component, results in the execution of arbitrary JavaScript within the victim’s browser. This code runs in the security context of that site, providing the attacker with the ability to steal session cookies, perform actions on behalf of the victim, or conduct further attacks.
Affected Systems
The vulnerability affects the Cute Editor for ASP.NET component version 6.4, specifically the colorpicker_more.aspx page that accepts a Theme parameter. It only impacts installations that include this component and are reachable via a web interface.
Risk and Exploitability
The CVSS base score is 6.1, indicating a medium level of severity, while the EPSS score is below 1%, suggesting that the likelihood of exploitation in the wild is currently low. The vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely without authentication; however, the victim must be already logged into the affected web application for the reflected script to execute. The exploit requires a malicious link that uses a crafted Theme parameter, which will be injected and reflected back into the page’s HTML, causing JavaScript execution.
OpenCVE Enrichment