Impact
This vulnerability in Allegra’s downloadAttachment method causes a cross‑site scripting flaw through insufficient validation of user‑supplied data. When a victim visits a malicious page or opens a crafted attachment, the injected script runs in the browser as the logged‑in user. The script can access session cookies, submit data, or perform unauthorized actions within the user’s context.
Affected Systems
All installations of Allegra are potentially affected; the CVE entry does not specify impacted versions, so any deployment of the Allegra platform remains vulnerable until updated.
Risk and Exploitability
The base score of 4.6 indicates moderate severity. No EPSS or KEV information is available, implying that the vulnerability has not yet been widely exploited. Attackers must lure a user to a malicious link or file, so successful exploitation requires user interaction. Nonetheless, the ability to run code in a user’s session poses a non‑negligible threat, especially in environments where users have elevated privileges.
OpenCVE Enrichment