Impact
The vulnerability arises from improper encoding or escaping of output when users perform the instance reset-password function in Apache CloudStack's web interface. If an attacker supplies malicious input that is reflected in the page without proper escaping, the browser will execute that input as script. The resulting cross-site scripting can be used to hij the victim's session, steal sensitive data, or perform further attacks against the CloudStack instance.
Affected Systems
Apache CloudStack releases from 4.15.1.0 through 4.20.3.0, and from 4.21.0.0 through 4.22.1.0, are affected. The Apache Software Foundation provides a fix in version 4.20.3.1 and 4.22.1.1, respectively, and any later release.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is the instance reset-password UI within the CloudStack web console. The vulnerability appears to require a user with authenticated access to the console who can trigger the reset-password functionality. Because the flaw allows arbitrary script execution when malicious input is reflected, an attacker who can influence the input can compromise the security of that user session. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog, but the risk depends on internal threat models and the level of exposure of the UI. The CVSS score of 9.1 indicates a high severity rating.
OpenCVE Enrichment