Impact
The vulnerability results from improper neutralization of user‑controlled input during web page generation in OceanicSoft Informatics Systems Ltd.’s ValeApp, allowing an attacker to embed arbitrary JavaScript into stored content. Once an attacker injects malicious payloads, other users’ browsers will execute the script when the content is rendered, enabling theft of session data, credential injection, or defacement.
Affected Systems
The flaw is present in all releases of ValeApp up through version 09072026. No later versions have been identified in the advisory, and the vendor has not released an update to address the issue.
Risk and Exploitability
The CVSS score of 9.3 classifies this weakness as critical. The EPSS score of less than 1% indicates a low probability of automated exploitation. Because the vulnerability is stored, the attacker must first submit malicious content that is preserved by the application and subsequently rendered to other users, so the exploitation requires access to an input mechanism such as a form or data entry interface. This inference is drawn from the description of a stored XSS flaw. The flaw is not listed in the CISA KEV catalog, suggesting limited observed exploitation.
OpenCVE Enrichment