Impact
The vulnerability is a stored XSS flaw that allows an attacker to inject malicious script into web pages served by the Gastromenum Ticket and QR Menu System. Because the input is improperly neutralized, the injected script can be executed in the browsers of any user who views the affected page, potentially enabling session hijacking, credential theft, or defacement. The weakness is identified by CWE‑79.
Affected Systems
The affected software is Gastromenum Ticket and QR Menu System version prior to 2026.08.31. No additional vendors or variants are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS data is unavailable, so the current probability of exploitation cannot be assessed. The vulnerability is not listed in CISA's KEV catalog, suggesting that known exploits have not yet been observed in the wild. The likely attack vector is via crafted input submitted through the application’s interface, which the system stores and later renders in a browser context without proper escaping.
OpenCVE Enrichment