Impact
Cross‑Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to inject and execute arbitrary JavaScript via ClientMessageController.java. The flaw, classified as CWE‑79, results in client‑side code execution that can hijack sessions, steal credentials, or modify page content. This potentially exposes sensitive data or user actions when the victim visits a crafted URL or submits a forged form.
Affected Systems
All deployed instances of the fuint Member Marketing System through version 1.0. Administrators should verify whether their environment runs any of those versions and consider upgrading or applying the vendor’s fix.
Risk and Exploitability
The attack vector is inferred to be a malicious HTTP request sent to ClientMessageController.java containing user‑controlled input that is reflected or executed in the victim’s browser. With a CVSS score of 6.1 the issue is moderate severity, and the EPSS score of less than 1 % indicates a low likelihood of current exploitation. The flaw is not listed in CISA KEV, and no exploited proof‑of‑concepts are publicly available.
OpenCVE Enrichment