Impact
Worksuite SaaS versions earlier than 6.0.14 contain a stored cross‑site scripting flaw in the Asset Management module that allows an authenticated administrator to enter malicious JavaScript in the Location and Description fields when creating a new asset. The payload is stored in the database and executed automatically in the browsers of any user who views the asset, potentially allowing an attacker to hijack sessions, steal credentials or perform arbitrary actions on behalf of the user. The vulnerability is classified as CWE-79 and carries a CVSS score of 4.6.
Affected Systems
The affected product is Froiden Worksuite SaaS. Any instance running a release prior to version 6.0.14 is vulnerable. Systems that allow administrators to create assets through the Asset Management interface are subject to this flaw.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. Exploitation requires that the attacker already possesses administrative privileges to create assets; non‑admin users cannot inject the payload. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no evidence of widespread exploitation at present. Nonetheless, the stored scripts can execute in any user’s browser that opens the malicious asset, creating a risk of session hijacking or credential theft if attackers can obtain admin access.
OpenCVE Enrichment