Impact
A DOM‑Based Cross‑Site Scripting flaw exists in th30d4y’s IP Reputation Checker. Unsanitized user input is rendered directly in the browser, letting an attacker inject and run arbitrary JavaScript. The attacker could hijack sessions, steal credentials, deface the site, or deliver further malware, affecting confidentiality and integrity of sensitive session data.
Affected Systems
The vulnerability affects th30d4y’s IP Reputation Checker component from version 1.0.1 up to, but not including, 2.0.1. Versions prior to 1.0.1 are not listed as affected, and the issue was resolved in 2.0.1.
Risk and Exploitability
With a CVSS score of 6.1 the flaw is considered moderate. No EPSS data is available and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Attackers must supply crafted input that a victim’s browser will interpret; no remote code execution or privilege escalation beyond the browser context is required.
OpenCVE Enrichment