Impact
Frogman’s chat‑console formatter injected user‑controlled fields as raw HTML, enabling attackers to embed JavaScript that runs when another administrator views the chat message. The malicious code executes with the viewer’s permissions, potentially granting the attacker the privileges of a legitimate admin.
Affected Systems
Frogman versions prior to 1.6.6 are vulnerable. The patch in version 1.6.6 correctly escapes HTML in the chat formatter. Administrators running any release older than 1.6.6 should upgrade to a fixed version.
Risk and Exploitability
The CVSS score of 4.8 denotes moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The exploit requires an attacker to insert malicious content into a chat message that a disparate administrator will view; it thus depends on insider threat or compromised internal accounts. Based on the description, it is inferred that the attack surface is limited to internal users, and because the payload runs with the viewer’s permissions, privilege escalation is possible in multi‑admin environments.
OpenCVE Enrichment