Impact
The vulnerability is an improper neutralization of input during web page generation that allows a reflected XSS flaw. This flaw enables an attacker to inject arbitrary JavaScript or HTML into pages rendered by the plugin. The description does not state specific downstream effects; the potential impact, based on the typical behavior of reflected XSS, could include execution of malicious code in a victim’s browser and related compromise of confidentiality, integrity, or availability.
Affected Systems
The affected product is Tribulant Software Newsletters (Newsletters Lite). Versions up to and including 4.9.9.6 are vulnerable; newer releases are not reported as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity. The EPSS score is <1%, suggesting that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted URL or form input that the plugin reflects into the page; no authentication is required, meaning any visitor can potentially trigger the flaw.
OpenCVE Enrichment
EUVD