Impact
A reflected cross-site scripting (XSS) vulnerability exists in the PHP Jabbers PHP Poll Script. An attacker can craft a specially crafted URL that, when a victim opens it, causes arbitrary JavaScript to be executed in the victim's browser. This flaw is fixed in version 4.1.
Affected Systems
The PHP Poll Script distributed by PHP Jabbers is affected when installed in any version earlier than 4.1. The script is publicly available on the PHP Jabbers website and can be deployed on any PHP‑enabled web server.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate severity. The EPSS score of less than 1 % suggests that exploitation attempts are expected to be infrequent. The vulnerability is not listed in CISA’s KEV catalog. Attackers can leverage the flaw remotely by sending a crafted link to unsuspecting users, with no authentication or privileged access required. Because the impact arises only when a victim visits the malicious URL, the risk is confined to the victim’s browser. However, due to the low EPSS and lack of exploitation in the KEV catalog, the likelihood of widespread exploitation is currently low.
OpenCVE Enrichment