Impact
The vulnerability in Menulux Portal is an Improper Neutralization of Input during web page generation, which allows an attacker to store a malicious script that is later rendered as part of the web page. This stored cross‑site scripting flaw is a classic example of CWE‑79 and can enable an attacker to execute arbitrary client‑side code, steal session cookies, hijack user sessions, deface the portal, or perform phishing and other client‑side attacks. The impact is confined to the browsers of users who view the affected page, yet the consequences can be severe for confidentiality and integrity of user accounts.
Affected Systems
Menulux Portal, released by Menulux Software Inc.; all versions prior to 20260903211448 are affected. The vulnerability is tied to the portal’s handling of user‑supplied content before that version.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score is currently unavailable, making the exact exploitation probability uncertain. Menulux Portal is not listed in the CISA KEV catalog. Attackers must submit malicious input to the portal, typically via an administrative or user interface that stores content. The injected script executes only when a browser renders the stored data, requiring the victim to access the portal; this limits the attack surface to browsers that can view the affected content but grants the attacker full authorized‑user privileges within the portal context.
OpenCVE Enrichment