Impact
The Blappsta Mobile App Plugin contains an improper neutralization of input during web page generation, allowing attackers to inject malicious scripts via crafted URLs. This reflected cross‑site scripting flaw can execute arbitrary client‑side code in the context of the victim's browser, enabling theft of credentials, session hijacking, or defacement of the site. The weakness is categorized as CWE‑79.
Affected Systems
The vulnerability affects nebelhorn's Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App for all releases up to and including version 0.8.8.8. Users running any earlier version are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity issue, while an EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. Likely exploitation would involve a remote attacker crafting a malicious URL that a user clicks, causing the injected script to run in the user's browser.
OpenCVE Enrichment