Impact
OutSystems Service Center allows a low‑privileged attacker to upload a file whose name contains JavaScript code. The malicious code is processed by the browser when the file attachment is prepared, creating a DOM‑based cross‑site scripting flaw (CWE‑79). If an employee or end user views the attachment, the attacker can execute arbitrary script in that browser context, potentially stealing credentials, defacing content, or facilitating further phishing attacks. The CVSS score of 4.8 indicates a moderate severity that can be exploited without special privilege beyond file‑upload capability.
Affected Systems
The product affected is OutSystems Service Center. All locations where a file can be attached and uploaded are vulnerable, regardless of the specific module or user role. The vulnerability was remedied in version 11.41.2 and later; installations older than that are impacted.
Risk and Exploitability
This is a DOM‑based XSS that requires a file upload with a crafted filename; the attacker does not need elevated permissions or system access. The CVSS score of 4.8 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likelihood of exploitation is uncertain but not negligible, especially in environments that allow frequent file uploads. The attack can compromise confidentiality, integrity, and availability on the client side of the application and may be leveraged to gain higher‑level access if further exploitation steps are taken.
OpenCVE Enrichment