Impact
The vulnerability permits authenticated users to embed arbitrary JavaScript into the application origin. By inserting malicious markup into a finding's severity field, the front‑end renders the content inside class and style attributes without escaping it, thereby executing attacker‑controlled scripts when the report is viewed.
Affected Systems
The flaw appears in Pentestify from maalfer. All releases prior to version 2.3.1 store the severity field without sanitization, leaving any such installation vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate impact. EPSS information is not available, and the issue is not listed in CISA’s KEV catalog. Exploitation requires an authenticated session with the ability to create or edit findings; the attacker crafts a payload in the severity field and triggers the report rendering to run JavaScript in the victim’s browser. The effect is confined to the client context and can lead to session hijacking or data theft within the application.
OpenCVE Enrichment