Impact
A reflected cross‑site scripting (XSS) flaw exists in Reportico Web up to version 8.1.0. An attacker can supply a malicious payload in the reportico_criteria parameter together with execute_mode=CRITERIA in run.php, causing the payload to be reflected and executed as JavaScript in the victim's browser. This allows client‑side code execution that can steal session data, deface the interface, or perform secondary attacks while the user remains authenticated to the application.
Affected Systems
The vulnerability affects the open‑source Reportico Web application, specifically versions reportico-web 8.1.0 or earlier. No other vendors or product lines are documented in this CVE entry.
Risk and Exploitability
Because the flaw is triggered by a standard HTTP request to a publicly reachable page and no authentication is required, an attacker can launch the exploit from anywhere. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, yet reflected XSS commonly has a high exploitation probability in environments lacking input filtering. The absence of a CVSS score precludes an exact severity metric, but the ability to run arbitrary JavaScript in the victim’s browser indicates a high impact.
OpenCVE Enrichment