Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that allows attackers to inject malicious scripts into pages served by the GNUCommerce plugin. This reflected XSS flaw means that any user who views a specially crafted page will have browser‑based code executed in their session, potentially leading to credential theft, session hijacking, or defacement. The weakness is classified as CWE‑79 and is not a remote code execution flaw, but it can enable attackers to manipulate the application state and compromise user accounts.
Affected Systems
The affected product is GNUCommerce by kagla, version 1.5.4 and earlier. Users running any release up to and including 1.5.4 should verify their installation and upgrade to a newer version where the issue is fixed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests that the probability of exploitation is currently very low. The flaw is not listed in the CISA KEV catalog, so widespread exploitation has not been observed. Attackers would need to lure victims to a crafted URL or input field to trigger the reflected script, which is feasible through phishing or social engineering.
OpenCVE Enrichment
EUVD