Impact
A vulnerability was identified in the Lagom WHMCS Template version 2.3.7 and earlier, affecting the component that implements Datatables. By manipulating certain user inputs, an attacker can cause the application to alter JavaScript object prototype properties, a flaw known as prototype pollution. This vulnerability can be triggered remotely and an exploit is publicly available, enabling an adversary to potentially modify application logic or inject malicious data.
Affected Systems
The affected product is Lagom WHMCS Template and all releases up to version 2.3.7 are impacted. Any deployment of these versions that utilizes the Datatables portion of the template is at risk because the vulnerability resides in the Datatables handling code.
Risk and Exploitability
The CVSS score for the issue is 5.1, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. However, the public nature of the exploit and the remote attack vector increase the likelihood of real‑world exploitation. Organizations using the affected template should treat this as a moderate risk and act promptly to remediate.
OpenCVE Enrichment