Impact
Azure Storage Explorer contains a cross-site scripting weakness that insufficiently sanitizes input in web page generation. If an attacker successfully injects malicious script, the script can run with the privileges of the compromised user, allowing the attacker to elevate privileges across the network. The flaw is a classic input validation issue identified as CWE-79, which can lead to unauthorized access and control over privileged operations.
Affected Systems
Microsoft Azure Storage Explorer is affected. No specific version information is listed, implying all published releases may potentially contain the flaw. Organizations that use Azure Storage Explorer should verify their installed version against the latest Microsoft update guidance.
Risk and Exploitability
The CVSS score of 8.8 labels this issue as high severity, reflecting significant impact if exploited. The EPSS score of less than 1% indicates a very low current exploitation probability according to publicly observed data, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector is inferred to be remote over a network, where an attacker can feed unsanitized input into the application. Given the high impact and moderate-to-high risk, timely remediation is advised.
OpenCVE Enrichment