Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing stored cross‑site scripting to be inserted into pages served by TR7 Cyber Defense Inc. WAF‑ASP. This flaw is a CWE‑79 type input validation weakness that permits attackers to embed malicious JavaScript into content that is later rendered for other users.
Affected Systems
TR7 Cyber Defense Inc. WAF‑ASP is affected, starting with version v1.0.324.900 and including all versions up to but not including v1.4.0.117. Users who maintain these releases are vulnerable until they upgrade beyond v1.4.0.117 or apply an equivalent fix.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. BecauseAF‑ASP processes content to generate web likely attack vector is a remote or local injection of malicious script via a web interface that stores user data. Successful exploitation requires that the injected script be stored and subsequently rendered, allowing execution of client‑side code in the context of other users who access the page.
OpenCVE Enrichment