Impact
The vulnerability is a reflected cross‑site scripting flaw in OSCAL‑GUI that is triggered by an attacker’s injection through the unsanitized "project" request parameter in oscal.php. By embedding malicious input in a URL, an attacker can break out of the JavaScript string and the body onload event handler, causing arbitrary scripts to run when a victim follows the link.
Affected Systems
The flaw affects OSCAL‑GUI, distributed by Brian Ruf. No explicit version information is supplied in the advisory, so any installation of OSCAL‑GUI may be vulnerable until a patched release is applied.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the vulnerability is exploitable without authentication via a crafted link. The EPSS score is not available, and the issue is not in CISA’s KEV catalog. If an infected user clicks the malicious URL, the attacker can execute arbitrary JavaScript in their browser, potentially leading to session hijacking, defacement, or delivery of additional payloads.
OpenCVE Enrichment