Impact
Photobooth versions prior to 1.0.1 contain a cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into unvalidated form input fields. The vulnerability enables the execution of arbitrary scripts in the context of the victim’s browser, potentially leading to session hijacking, defacement or phishing attacks. This weakness is identified as CWE‑79, a classic cross‑site scripting issue.
Affected Systems
The flaw affects the Photobooth application developed by lukas12000, specifically all releases before version 1.0.1. Users deploying earlier versions are exposed to the described XSS risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild as of the latest data, and the vulnerability is not listed in the CISA Known Exploit Vulnerabilities catalog. The likely attack vector involves a malicious user submitting crafted input through the public user-facing form fields within Photobooth. An attacker can trigger the vulnerability without requiring additional privileges or exploits against the host system.
OpenCVE Enrichment