Impact
The vulnerability is a reflected cross‑site scripting flaw located in the error page component of the XMLRPC-C Library. An attacker can inject malicious script code that is executed in the victim’s browser when the error page is displayed, potentially allowing theft of session data, credential injection, or other client‑side attacks. The weakness is a classic input validation failure identified as CWE‑79.
Affected Systems
Affected products are the XMLRPC-C Library, version range 1.07 through 1.67.01. Systems running any of these releases are at risk; newer releases starting from version 1.68 are considered safe.
Risk and Exploitability
The CVSS score of 8.2 signals a high‑severity flaw. The EPSS score is 0.00268, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation at the time of analysis. The likely attack vector is a remote web user who can trigger the error page by sending a crafted request to the XMLRPC‑C service; infection requires user interaction with the victim’s browser when the page is rendered.
OpenCVE Enrichment