Impact
The vulnerability is a Cross‑Site Scripting flaw present in Cockpit CMS versions 2.13.5 and earlier. It arises in the item.php file and the JavaScript modules field‑select.js and tags.js, allowing an attacker to supply malicious input that is reflected and executed as script in the browsers of visitors who view the affected pages. The result is that a remote attacker can execute arbitrary code in the context of the CMS, potentially undermining site data integrity and control.
Affected Systems
The vulnerability affects Cockpit CMS versions 2.13.5 and all earlier releases. No specific vendors or products were listed beyond the Cockpit CMS title, and the affected‑version information indicates the issue exists in 2.13.5 and past releases.
Risk and Exploitability
The CVSS score is 6.1, indicating a moderate severity, and the EPSS score is <1%, meaning the probability of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely via a web request, indicating a high potential impact for the system and its users. The lack of publicly documented exploits suggests the risk is not yet high, yet the ability to execute arbitrary code renders it a priority to remediate.
OpenCVE Enrichment