Impact
The vulnerability is a stored cross‑site scripting flaw in Bynder version 0.1.394. Attackers can inject HTML or JavaScript that is retained in the application and later served to users. This allows the attacker to execute code within the victim’s browser, potentially enabling credential theft, site defacement, or other client‑side attacks. Note that the supplier disputes the validity of version 0.1.394, stating that it was never a valid build and that the environment in which the flaw was found is not publicly documented. This weakness is classified as CWE‑79.
Affected Systems
This flaw affects the Bynder web application at version 0.1.394. No other versions or vendors are listed in the CNA data. Users running this specific build are at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of 0.00138 reflects a very low but non‑zero exploitation probability. The vulnerability was publicly disclosed, suggesting the risk of exploitation is non‑negligible. The issue is not yet catalogued in CISA’s KEV list; however, the stored nature of the payload means an attacker could trigger it via legitimate user interactions, making it potentially effective against unsuspecting users. The attack vector is inferred to be through the application’s content management interface, requiring user authentication and content delivery to the victim’s browser.
OpenCVE Enrichment