Impact
A remote cross‑site scripting flaw exists in the Support chatbot of Nopaperforms Niaa‑Chatbot. The flaw allows an attacker to input an arbitrary email address that is not validated, enabling the injection and execution of any web script or HTML. Successful exploitation can lead to theft of user credentials, session hijacking, or the delivery of malicious content in the victim’s browser, thereby compromising confidentiality and integrity of the application and its users.
Affected Systems
The vulnerability affects releases of Nopaperforms Niaa‑Chatbot dated on or before 2022‑05‑17. The chat support component processes an "Enter email" field from users without proper sanitization, making earlier versions susceptible. No product version is listed as patched in the supplied data, indicating that at the time of disclosure the affected component lacked a fix.
Risk and Exploitability
The CVSS score of 6.1 marks it as medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not currently included in the CISA KEV catalog. Attackers can reach the vulnerable parameter via the normal web interface, without requiring elevated privileges or local access.
OpenCVE Enrichment
EUVD