Impact
A stored cross‑site scripting weakness allows an authenticated user to submit malicious content that, when viewable by another authenticated user, runs arbitrary JavaScript within that user's session. This can lead to actions performed on behalf of the victim and potentially result in the compromise of higher‑privileged accounts. The flaw is an example of improper handling of user input and output in the application layer.
Affected Systems
The vulnerability is present in Kiteworks Core versions prior to 9.5.0; any instance of the product running an affected version is at risk.
Risk and Exploitability
With a CVSS score of 8.7, the flaw is considered high severity. Although the EPSS score is not listed, the vulnerability is exploitable by any authenticated user who can post content and by victims who subsequently view that content. The impact is limited to accounts that view the injected data, but the potential for account takeover of higher‑privileged users raises the overall risk. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment