Impact
The vulnerability is an improper neutralization of input during web page generation in Thales Sentinel LDK Runtime on Windows, leading to stored cross‑site scripting. An attacker can embed malicious JavaScript that will be automatically rendered when users view the affected page, enabling local script execution. This can result in session hijacking, data theft, defacement, and manipulation of the user interface. The flaw is classified as CWE‑79.
Affected Systems
The issue affects the Sentinel LDK Runtime product from Thales, deployed on Windows. Versions older than 10.22 are vulnerable.
Risk and Exploitability
The CVSS score of 7 signals a high severity, while the EPSS score of < 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector is the web interface that accepts user input; an attacker could inject malicious content via submitted payloads. The stored nature of the payload allows it to be served to any user who views the affected page until the application is patched or the data is removed.
OpenCVE Enrichment