Impact
BilPark Informatics Technologies Industry and Trade Inc.’s DoXBASE contains an improper neutralization of input during web page generation, resulting in reflected cross‑site scripting. The flaw allows an attacker to inject malicious scripts that execute in the victim’s browser, potentially enabling session theft, defacement of the web interface, or the injection of additional malware through the user’s context.
Affected Systems
BilPark Informatics Technologies Industry and Trade Inc.’s DoXBASE, affected through and including version 27082026. No other affected versions are listed.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower but non‑negligible risk. The likely attack vector is client‑side: an attacker would craft a malicious URL or input that, when viewed or processed by a user of DoXBASE, leads to execution of injected scripts. Successful exploitation could compromise user sessions and expose sensitive data within the web application’s domain.
OpenCVE Enrichment