Impact
A stored cross‑site scripting flaw (CWE‑79) in the Repetico web backend lets an authenticated user submit malicious JavaScript into the text field of a multiple‑choice question. When the question is later displayed by the Android client, the payload runs in the app’s JavaScript context, giving the attacker permission to execute arbitrary scripts within the application.
Affected Systems
The vulnerability exists only in the Repetico web backend, version 1.9.7.31 for Android. No other vendors, product lines or versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium‑severity flaw, while the EPSS score of less than 1% suggests a low probability of current exploitation; the vulnerability is not in the CISA KEV catalog. Exploitation requires a remote authenticated user to upload a malicious question, after which any viewer of that question on the Android app will have the embedded script executed in the app’s context.
OpenCVE Enrichment