Impact
An attacker can construct a malicious link that, when clicked by an authenticated user, causes the victim’s browser to execute attacker‑supplied JavaScript. The injected code runs with the user’s credentials, enabling session theft, credential phishing, or other malicious actions within the Secret Server application.
Affected Systems
Delinea Secret Server On‑Prem, versions prior to 12.0.20. No other vendors or products are affected.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical, yet the EPSS score of less than 1% indicates a very low probability of public exploitation at present. It is not yet listed in CISA’s KEV catalog. Exploitation requires user interaction—the user must click the crafted link, typically delivered via phishing or other social‑engineering techniques. Once activated, the victim’s browser runs the injected code without additional privileges.
OpenCVE Enrichment