Impact
The vulnerability is an improper neutralization of input that allows an authenticated attacker to inject malicious code into forms. When the altered form is subsequently displayed to other users, the embedded script is executed in their browsers, enabling theft of session cookies, unauthorized actions, or data exfiltration. This stored cross‑site scripting can compromise confidentiality, integrity, and possibly availability of data viewed through the form interface.
Affected Systems
The issue affects the Kiteworks Secure Data Forms product from Kiteworks, with all installations prior to version 9.2.1 being vulnerable. Upgrading to version 9.2.1 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an authenticated user who can modify a form; the attacker must create a malicious input that is stored and later rendered to victims. Once the page is viewed, the injected script runs in the victim’s browser, making the attack straightforward for an insider with sufficient privileges.
OpenCVE Enrichment