Impact
The vulnerability is caused by improper neutralization of input when generating web pages, allowing reflected cross‑site scripting. An attacker can inject malicious scripts into the page, which then run in the browsers of users who view the page. Such scripts can hijack sessions, steal credentials, deface the site, or perform phishing or other client‑side attacks.
Affected Systems
LambertGroup Responsive HTML5 Audio Player PRO With Playlist is affected in all releases through version 3.5.8. No later versions have been identified as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply crafted input—such as a malicious URL or form submission—to trigger the reflected XSS, after which they could execute arbitrary scripts in the victim’s browser. The impact is confined to that browser session but can lead to serious user‑level compromise.
OpenCVE Enrichment
EUVD