Impact
Mettle SendPortal versions 3.0.1 and earlier contain a stored cross‑site scripting flaw in the template management feature. The application fails to sanitize input in the content field of the /templates endpoint, allowing an attacker to embed malicious JavaScript that is permanently stored. When a user loads the affected template in their browser, the injected script executes in the victim’s context, enabling any client‑side actions the attacker chooses.
Affected Systems
Mettle SendPortal version 3.0.1 and all earlier releases are impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack method involves an adversary creating or editing a template using the unsanitized content field; if a target user views the template, the injected JavaScript runs in their browser, allowing arbitrary client‑side script execution.
OpenCVE Enrichment