Impact
Capgo versions prior to 12.128.2 allow an attacker to inject arbitrary HTML into the organization settings page through the organization name field. The injected markup can contain a redirect link that sends users to any external site, creating a phishing vector and subjecting the organization to reputation damage. This is a CWE-79 vulnerability.
Affected Systems
The vulnerability affects the Capgo platform, specifically all releases before version 12.128.2. Based on the vulnerability description, it is inferred that users with permission to edit organization settings are at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity and the EPSS score of < 1% indicates a very low exploitation probability. Based on the description, it is inferred that the attack requires access to the organization settings endpoint, typically granted to administrators or users with elevated privileges, and relies on a victim clicking the injected link. While no remote code execution is possible, the redirect can be used for phishing or to deliver malicious content to users.
OpenCVE Enrichment