Impact
The Guardian language‑system contains a flaw where the id GET parameter is inserted without sanitization into several HTML form action attributes in text_file.php. An authenticated attacker can craft a malicious URL that injects <script> tags, causing client‑side code execution within the victim’s browser session. This cross‑site scripting allows the attacker to run arbitrary script with the privileges of the logged‑in user, but it does not modify server data.
Affected Systems
The Guardian language‑system is the only product mentioned. No specific version numbers are listed, so all released versions of this product are potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 4.8 classifies the weakness as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not currently included in CISA’s KEV catalog. Because an authenticated user must generate the malicious URL, the likely attack vector is a web‑based exploit that requires a user with legitimate access to the affected page. The overall risk remains moderate, bounded by the necessity of authenticated access and the limited impact to client‑side execution only.
OpenCVE Enrichment