Impact
Improper neutralization of user-supplied input in the Brainstorm Force Astra Bulk Edit plugin causes a DOM‑based XSS flaw. The plugin does not sanitize data before embedding it in the rendered web page, allowing an attacker to execute arbitrary JavaScript in the victim’s browser. This vulnerability is classified as CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
The flaw is present in all released versions of the Astra Bulk Edit plugin up to and including version 1.2.10. No earlier release dates are specified; the vendor notes that the issue exists from 'n/a through <= 1.2.10', meaning any version prior to a patch is affected.
Risk and Exploitability
The CVSS base score is 6.5, indicating moderate severity. The EPSS score is reported as below 1 %, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation reports are available. Exploitation requires an attacker to craft input that the plugin processes and for a user to load the resulting page, typically via a malicious link or form. Attackers cannot modify data on the server but can execute scripts within the context of the victim’s browser.
OpenCVE Enrichment