Impact
The vulnerability is an improper neutralization of script‑related HTML tags, classified as a basic XSS (CWE‑80). An attacker can embed malicious JavaScript into a response that is rendered by a victim's browser. This could allow the attacker to steal session cookies, deface the application, or redirect the victim to a phishing site.
Affected Systems
Softtr Informatics Technology Trading Limited Company E‑Commerce Pack, all releases prior to version 5.03.01.49. The problem exists in the product’s input handling prior to that version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate overall severity, and the EPSS score is not available, suggesting low but uncertain exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need a victim to load a crafted page or provide malicious input that the application echoes without proper encoding, making exploitation easier in a web‑based context.
OpenCVE Enrichment