Impact
SIP version 5.2.16 contains a stored XSS flaw that lets attackers inject arbitrary JavaScript by embedding malicious scripts within program names submitted via HTTP requests. Because the platform renders program names without output encoding, the injected code executes in any user’s browser that views the affected page, giving the attacker the ability to run scripts in the victim’s browser and potentially compromise the confidentiality and integrity of data accessed during that session.
Affected Systems
The vulnerability affects Dan‑in‑CA Sustainable Irrigation Platform, specifically version 5.2.16 and any earlier releases that process user‑supplied program names without sanitization. Any installation that accepts program names via HTTP requests and renders them in the web interface is susceptible.
Risk and Exploitability
The CVSS score is 5.3, the EPSS score is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending malicious program name payloads through HTTP requests without needing a passphrase; the default passphrase "opendoor" does not provide a barrier to unauthorized access. Because the stored data is rendered in a web page, its exploitation requires the attacker to have an affected user view the stored program name, but the low EPSS indicates a moderate overall risk with a low probability of exploitation.
OpenCVE Enrichment