Impact
A reflected cross‑site scripting flaw exists in the Reportico Web application. The vulnerability allows remote attackers to inject arbitrary JavaScript in the reportico_criteria parameter used by run.php when execute_mode=CRITERIA. An attacker can trigger the flaw with a standard HTTP request, causing the malicious script to be reflected in the response and executed in the victim’s browser. Based on the description, it is inferred that such client‑side code execution could be used to deface the interface, harvest session information, or launch further attacks while the user remains authenticated.
Affected Systems
The Reportico Web application up to and including version 8.1.0 is vulnerable. No other vendors or product lines are documented in this CVE entry.
Risk and Exploitability
The issue is triggered by a publicly reachable HTTP request and does not require authentication, therefore an attacker can exploit it from any location. The CVSS score of 6.1 indicates a medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog, but reflected XSS can achieve significant impact when input is not properly sanitized.
OpenCVE Enrichment