Impact
This vulnerability is an improper neutralization of input during web page generation, categorized as a Cross-site Scripting flaw. An attacker can supply crafted input that is reflected back in the response without adequate sanitization, enabling the injection of malicious scripts into the browser context of any user who views the affected page. The potential consequences include session hijacking, defacement, theft of user credentials, and execution of arbitrary code within the victim’s browser. The weakness corresponds to CWE-79, a classical XSS problem.
Affected Systems
The flaw is present in the CaptionPix plugin developed by Russell Jamieson, affecting all installed copies from the earliest release through version 1.8 inclusive. No earlier or later versions are known to be vulnerable.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. The EPSS score of less than 1% suggests that, at the time of assessment, exploitation likelihood is very low. The issue is not listed in CISA’s KEV catalog. The vulnerability is believed to be exploitable remotely by sending a crafted HTTP request to the plugin’s exposed interfaces, and the attacker does not need privileged access to the server to launch the attack.
OpenCVE Enrichment
EUVD