Impact
Omega-PSIR is vulnerable to a reflected cross‑site scripting flaw that can be triggered through the lang parameter. By opening a specially crafted URL, an attacker can cause arbitrary JavaScript to execute in the victim’s browser. The vulnerability can lead to credential theft, session hijacking, defacement or malicious content injection.
Affected Systems
Politechnika Warszawska’s Omega‑PSIR product is affected, specifically versions earlier than 4.6.7. The issue was resolved in version 4.6.7.
Risk and Exploitability
The impact is Medium with a CVSS score of 5.1, and the EPSS score is below 1%, indicating low to very low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Because it is a reflected XSS for a browser‑based parameter, an attacker can exploit it remotely by having a victim visit a malicious link. Successful exploitation would allow the attacker to inject and execute scripts in the victim’s local context.
OpenCVE Enrichment