Impact
NewSiteServer (NSS) by CyberTutor allows unauthenticated remote attackers to upload arbitrary files, including malicious HTML. This can lead to cross‑site scripting attacks that compromise the confidentiality and integrity of data accessed by the site’s users.
Affected Systems
The affected product is CyberTutor NewSiteServer (NSS). No specific affected versions were provided, so any deployed instance remains vulnerable until a vendor‑issued solution is applied.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack vector is remote and unauthenticated, relying on the upload interface. Exploitation would require an attacker to send a crafted file to the vulnerable endpoint, leading to executed client‑side code via injected HTML.
OpenCVE Enrichment