Impact
Guardian language‑system does not perform output encoding or input validation on the id GET parameter before inserting it into several HTML form action attributes in text_file.php. As a result an authenticated attacker can craft a URL that injects <script> tags, which are then executed in the victim’s browser session. This client‑side code execution is a classic Cross‑Site Scripting (CWE‑79) flaw that enables malicious JavaScript to run with the permissions of the logged‑in user but does not alter the server state or compromise server‑side data directly.
Affected Systems
The Guardian language‑system is the only product mentioned. No specific version numbers are listed, so all released versions of this product are potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 4.8 classifies the weakness as moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not currently included in CISA’s KEV catalog. Because an authenticated user must generate the malicious URL, the likely attack vector is a web‑based exploit that requires a user with legitimate access to the affected page. The overall risk remains moderate, bounded by the necessity of authenticated access and the limited impact to client‑side execution only.
OpenCVE Enrichment