Impact
The flaw allows an authenticated user to craft a URL that includes script tags in the name query parameter. Because the application fails to sanitize that value before inserting it into an HTML input field, the browser executes the embedded JavaScript within the victim’s session. This can result in theft of session cookies, malicious redirection, or unauthorized manipulation of page content.
Affected Systems
All installations of the Guardian Language‑System that include the designer.php page and have not applied the vendor’s fix are affected. The vulnerability description does not specify a version range, so any deployment running the unpatched code is at risk.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity. An EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to be authenticated and capable of requesting designer.php, and the impact is confined to client‑side operations within the user’s browser.
OpenCVE Enrichment