Impact
The vulnerability arises from improper neutralization of user-supplied input during web page generation, enabling attackers to inject malicious scripts that execute in the victim’s browser. This reflected XSS can lead to session hijacking, credential theft, or the execution of arbitrary JavaScript within the user’s environment, as identified by CWE-79. The impact is confined to the client side but can compromise sensitive data and user trust.
Affected Systems
KA Informatics Technologies Ltd. Co. operates the Bar Association Website, which is vulnerable through all releases up to 18092026. The vendor has been notified of the disclosure but has yet to respond or publish a fix, leaving the public‑facing application exposed.
Risk and Exploitability
The CVSS score of 6.1 classifies this flaw as moderate, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a crafted URL or input field that echoes a user‑provided value back to the page, allowing an attacker to embed JavaScript that runs in the context of any user who visits the page.
OpenCVE Enrichment