Impact
The vulnerability allows a malicious payload in an "argument code" parameter to be reflected into the web page and executed by the victim’s browser, creating a classic reflected cross‑site scripting weakness (CWE‑79). The same flaw also permits execution of arbitrary code fragments, making it a code‑injection vulnerability (CWE‑94). The affected functionality is not fully described, but the ability to inject and run scripts remotely is the primary impact.
Affected Systems
The flaw compromises Stephen‑Kruger Bluebox versions up to and including 4.5.12. Users running any of these releases are potentially exposed until a patch is applied or mitigated. No other versions were identified as affected in the current advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of public exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by manipulating the "argument code" parameter; because the payload is reflected into browser‑side code, successful exploitation results in the execution of arbitrary scripts within the victim’s browsing context.
OpenCVE Enrichment