Impact
The vulnerability resides in the Private Message Handler’s index.tpl.php file, where a manipulation of the nickname argument leads to script code being injected into the page. The flaw allows an attacker to embed malicious JavaScript in page responses, which is executed in the victim’s browser. This can be used to steal session data, deface the site or facilitate further attacks. The weakness is classified as input validation and code injection: CWE‑79 and CWE‑94.
Affected Systems
InstantSoft’s icms2 content management system versions up to and including 2.18.2 are affected. The vulnerability impacts the public index feature handling private messages and requires the system to be online in order for the flaw to be exploitable.
Risk and Exploitability
The flaw is rated CVSS 5.1, indicating a moderate severity. The EPSS score is not available and the vulnerability is not listed in the National Cybersecurity Center’s KEV catalog. The description confirms that the attack can be launched remotely and that the exploit has been publicly disclosed, implying a real‑world risk if patches are not applied.
OpenCVE Enrichment