Impact
The identified weakness is a cross-site scripting flaw in the Add Account Group function of yaffa version 2.0.0. An attacker can deliver malicious JavaScript that runs in the browser of anyone who views the affected account‑group page. The injected script has full access to the client’s execution context, allowing cookie theft, session hijacking, or further in-page manipulation.
Affected Systems
The vulnerability impacts the yaffa web application, specifically the 2.0.0 release listed on the public GitHub repository. No CNA vendor product information is provided, and the source code is openly available. Users running this version and exposing the account‑group page over the network are susceptible.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, and the EPSS score of less than 1% suggests low current exploit probability. Because the flaw is web-based, an attacker only needs to persuade a user to load the manipulated page, which can be achieved via phishing, social engineering, or compromise of the site. The vulnerability is not yet recorded in the CISA KEV catalog, and there is no patch or official workaround disclosed.
OpenCVE Enrichment
Github GHSA