Impact
The flaw allows an "argument code" that is reflected into the page and executed by the victim’s browser, creating a classic reflected cross‑site scripting vulnerability (CWE‑79). The same vulnerability also permits execution of arbitrary code fragments, falling under the code‑injection weakness (CWE‑94).
Affected Systems
The vulnerability affects Stephen‑Kruger Bluebox versions up to and including 4.5.12. Users running any of these releases are potentially exposed until a patch is applied or mitigated. No other versions were identified as affected in the current advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, with an EPSS score of less than 1% suggesting a very low likelihood of public exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog, further indicating limited exploitation evidence. Attackers can execute the exploit remotely by manipulating the "argument code" parameter; because the payload is reflected into browser‑side code, successful exploitation results in the execution of arbitrary scripts within the victim’s browsing context.
OpenCVE Enrichment