Impact
The flaw is a stored cross‑site scripting vulnerability in Squirro Cognitive Search versions older than 3.14.2. It permits a remote attacker to inject and execute arbitrary code through the Email Notification, Create Evaluation Sets and HTML Editor features. Based on the description, it is inferred that the injected code runs in the context of any user who views the affected content, effectively turning the XSS into a remote code execution vector.
Affected Systems
All installations of Squirro Cognitive Search with a build earlier than 3.14.2 are affected. Versions below 3.14.2 do not sanitize or properly escape input to the Email Notification, Create Evaluation Sets, or HTML Editor components, leaving the application vulnerable.
Risk and Exploitability
The CVSS base score of 6.1 indicates medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown. The flaw can be exploited if the endpoints that accept untrusted input are reachable; based on the description, it is inferred that the risk is higher for publicly exposed or internally exposed services that have not been restricted or patched.
OpenCVE Enrichment