Impact
The vulnerability is an improper neutralization of input during web page generation, resulting in reflected Cross‑Site Scripting. This flaw allows an attacker to inject malicious JavaScript into responses that are displayed to site visitors. If executed, client‑side code could steal session cookies, execute unauthorized actions, or redirect users, compromising confidentiality and integrity of user data.
Affected Systems
AcuGIS Leaflet Maps, developed by David Ghedini, is affected through all releases up to and including version 5.1.1.0. Sites that have older or equal versions of the plugin are vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating a high risk for applications that expose the plugin’s input handling. The EPSS is below 1 %, suggesting a low probability that attacks are currently being executed in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to craft a URL or provide input that the plugin reflects without sanitization, so a user must visit or interact with a malicious link. Successful exploitation will remain at the client side and does not elevate privileges on the server.
OpenCVE Enrichment
EUVD