Impact
The vulnerability arises from improper input handling: user‑supplied firstName, lastName, and nickname fields are stored without sanitization (CWE‑20, CWE‑116) and later rendered with Vue’s v‑html directive as part of StringHighlighter.js (CWE‑79). This combination also leverages character‑encoding mishandling (CWE‑183), making the platform vulnerable to Stored XSS. An attacker who registers a user with a small HTML payload, such as an <img> tag that triggers JavaScript, can cause arbitrary code execution in an administrator’s browser when the admin visits the Quiz Runs page. This enables the attacker to take full control of the application, including creating backdoor accounts, deleting projects, or exfiltrating data.
Affected Systems
National Security Agency’s skills-service, known as SkillTree, is vulnerable in all releases prior to version 4.4.2. Version 4.4.2 contains the vendor supplied patch that removes the three exploitable attack paths. The product is a micro‑learning gamification platform.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. No EPSS score is published, but the attack requires only a legitimate registration with a payload up to 30 characters and no additional social engineering, making exploitation highly feasible. While not yet listed in CISA KEV, the ability to execute arbitrary code in an administrator’s browser signals a high likelihood of real‑world exploitation once visibility of the CVE is established.
OpenCVE Enrichment