Impact
The vulnerability is an improper neutralization of user input during web page generation. It allows a DOM-based XSS that can be triggered when a user visits a page that renders the plugin.
Affected Systems
Affected systems are installations of the hupe13 Extensions for Leaflet Map plugin version 5.1 or earlier. The vulnerability exists in all releases from the plugin's inception through 5.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Likely attack vector is remote, via a crafted URL or payload that a user of the site might follow. Once exploited, the attacker can run malicious scripts in the victim’s browser, steal session cookies, or perform further actions.
OpenCVE Enrichment