Impact
A reflected cross‑site scripting vulnerability exists in Reportico Web versions 8.1.0 and earlier. By supplying a malicious payload in the loadTemplate parameter together with execute_mode=PREPARE to run.php, an attacker can cause a victim’s browser to execute arbitrary JavaScript.
Affected Systems
The vulnerability affects installations of Reportico Web up to and including version 8.1.0. Systems running newer versions that no longer expose the vulnerable loadTemplate parameter or that properly sanitize the input are not impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity reflected XSS. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. An attacker can exploit this vulnerability by crafting a URL that includes a malicious loadTemplate value; any user encountering such a URL can have arbitrary JavaScript executed in their browser. The risk is contingent on exposure to untrusted input and the likelihood of users visiting crafted links.
OpenCVE Enrichment