Impact
The vulnerability in DivvyDrive arises from insufficient neutralization of user input during web page generation, allowing malicious scripts to be stored in the application’s data store (C compromised field is rendered in a browser, the injected script executes with the privileges of the user viewing the page or other sensitive information.
Affected Systems
Affected are versions of DivvyDrive before 4.8.3.1, including the 4.8.2.23 build and all earlier releases from the same vendor.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in KEV catalog. The attack vector is inferred to require an actor who can submit or modify content that is stored by the application; after the malicious payload is persisted, it will run in the browsers of any users who later view the affected content.
OpenCVE Enrichment