Impact
A stored cross‑site scripting (XSS) flaw exists in the H5P module "h5p-nodejs-library" that allows an attacker to upload H5P content containing malicious JavaScript. When another user views the compromised H5P content, the embedded script runs in their browser, potentially allowing the attacker to steal session cookies, deface pages, or conduct further phishing attacks. This flaw is based on improper input validation (CWE‑79) and unsafe handling of file extensions (CWE‑20).
Affected Systems
The vulnerability affects Lumi Education UG’s h5p-nodejs-library product in all versions up to and including 10.0.4. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to upload malicious content through the module’s file‑upload interface, which is then rendered to other users. Because the flaw relies on extension‑based filtering alone, an attacker can choose an allowed extension (e.g., XML) and embed harmful JavaScript, making the risk significant for sites that do not employ additional content validation. However, the impact is limited to client‑side execution and does not provide remote code execution on the server itself.
OpenCVE Enrichment