Impact
Improper neutralization of input. Malicious content stored in the application can be rendered in every browser that accesses the affected page, allowing an attacker to execute arbitrary client‑side scripts. This can lead to or other client‑side compromises as defined by CWE‑79.
Affected Systems
Webremium Istanbul Web Design’s Mezunum Satiyorum, versions 1.2.504 through 10072026, are affected. No other vendors or products are listed as impacted. The vendor did not respond to early disclosure, leaving the issue unresolved at this time.
Risk and Exploitability
The CVSS base score of 6.4 classifies the risk as moderate. The EPSS score of less than 1% indicates a low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The most likely attack vector is that an attacker posts malicious content via the application, then persuades a legitimate user to view the stored data, at which point the injected script runs. Because vulnerability may remain exploitable for an extended period.
OpenCVE Enrichment