Impact
A reflected Cross‑Site Scripting (XSS) flaw exists in Clickedu’s "/user.php/" endpoint. An attacker can embed malicious JavaScript in a URL that, when visited by a user, runs in the victim’s browser. This can steal session cookies and enable the attacker to perform unauthorized actions on the user’s behalf.
Affected Systems
The flaw affects Sanoma Clickedu before version 5.1. The vendor released a fix in Clickedu 5.1.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not have widespread exploitation yet. Attackers can use the flaw by crafting a malicious URL and luring users to it, which can be carried out remotely without authentication.
OpenCVE Enrichment