Impact
The vulnerability is a client‑side Cross Site Scripting flaw in Omeka S 4.2.0 that is triggered by the site navigation custom URL function. When a crafted URL is processed, the input is not properly sanitized, allowing an attacker to inject script that executes in the victim’s browser. This arbitrary code execution opens the possibility of executing any JavaScript code supplied by the attacker during a normal navigation action.
Affected Systems
The affected product is Omeka S, version 4.2.0. No other vendor or product information is provided in the CNA data.
Risk and Exploitability
The CVSS score is 6.1, but the presence of a XSS vulnerability that results in arbitrary code execution indicates a medium severity risk. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an attacker submitting a crafted URL or manipulating the navigation custom URL feature, inferred from the description. Exploitation requires no special privileges on the target site and can be achieved by any user who can visit the vulnerable link.
OpenCVE Enrichment