Impact
HP App for Android is vulnerable to cross-site scripting when an outdated version is used. The flaw allows an attacker to inject and execute malicious scripts within the app’s web views, potentially compromising user session data, injecting counterfeit content, or executing arbitrary actions on the device. This weakness is documented as CWE-79.
Affected Systems
The affected product is HP Inc’s HP App for Android. Any installation running an outdated version of the app is susceptible; no specific version numbers are supplied.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% and absence from the KEV catalog suggest a low probability of exploitation in the wild. The vulnerability likely requires the user to interact with malicious content or a compromised web page served within the app, making remote exploitation less straightforward.
OpenCVE Enrichment