Impact
The defect is a stored Cross‑Site Scripting flaw in the application logo upload functionality of MyComplianceOffice MCO. An attacker who is able to upload or replace the application logo can embed a malicious SVG file that contains JavaScript. When the logo is rendered or opened by a user, the embedded script runs in the victim’s browser, providing client‑side code execution. The vulnerability leads to script injection without granting any server‑side privileges. The weakness is a classic input validation failure (CWE‑79).
Affected Systems
MyComplianceOffice MCO. The issue has been confirmed in version 25.3.3.1; other versions may also be vulnerable, but this has yet to be verified.
Risk and Exploitability
The CVSS score of 4.8 labels it as low severity. With an EPSS score of < 1%, the chance of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. An attacker needs an account with permission to upload or modify the application logo, usually administrators or users with configuration rights. Execution is limited to the victim’s browser session and does not elevate privileges on the server.
OpenCVE Enrichment