Impact
The vulnerability arises from improper neutralization of user input during the generation of web pages in Seres Software syWEB, allowing attackers to inject and execute arbitrary JavaScript when a victim visits a crafted URL. This reflects a typical injection weakness identified as CWE‑79 and can lead to theft of session cookies, service compromise, or defacement.
Affected Systems
Affected are all installations of SyWEB from the vendor Seres Software up to, and including, version 27082026. The product is no longer supported, so no official patch is currently available.
Risk and Exploitability
Based on the CVSS score of 6.1, the flaw is of moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating that no public exploit has been recorded yet. Attackers can likely exploit the flaw simply by sending a maliciously crafted link or embedding the URL in social media or email; no authentication or privileged access is required.
OpenCVE Enrichment