Impact
The flaw is a Cross‑Site Scripting (XSS) vulnerability that exists in the file item.php and the JavaScript files field‑select.js and tags.js of Cockpit CMS. An attacker can supply malicious input that is reflected in a way that allows script execution in the browsers of users who view the affected pages. The impact is that a remote user can execute arbitrary code within the context of the CMS, potentially compromising the site’s data and control.
Affected Systems
The vulnerability affects Cockpit CMS versions 2.13.5 and all earlier releases. No specific vendors or products were listed beyond the Cockpit CMS title, and the affected‑version information indicates the issue exists in 2.13.5 and past releases.
Risk and Exploitability
No CVSS score is available and the EPSS score is unknown, but the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely via a web request, indicating a high potential impact for the system and its users. The lack of publicly documented exploits suggests the risk is not yet high, yet the ability to execute arbitrary code renders it a priority to remediate.
OpenCVE Enrichment