Impact
The flaw is an improper encoding or escaping of output in Apache CloudStack’s administration UI when using the Lock User feature. An attacker can inject malicious script into the user lock form or resulting pages, leading to a stored or reflected cross‑site scripting condition. Successful exploitation would allow the attacker to execute arbitrary JavaScript in the context of the administrative interface, potentially enabling session hijacking, credential theft, or lateral movement within the application.
Affected Systems
Apache Software Foundation’s Apache CloudStack version 4.20.0.0 up to and including 4.20.3.0 and versions 4.21.0.0 through 4.22.1.0 are vulnerable. The vulnerability only exists when the Lock User function is used in the UI; it does not affect API calls or other components.
Risk and Exploitability
The CVSS score is 4.8, and the EPSS score is < 1%, indicating a very low probability of exploitation. The attack surface is the web UI and therefore accessible to anyone who can reach the management server, making it a high convenience risk. The vulnerability is not listed in CISA’s KEV catalog, but it remains a serious XSS that could be abused for privilege escalation or data exfiltration if an attacker can compromise an administrator’s session.
OpenCVE Enrichment