Impact
Rejetto HFS instances running versions 3.0.0 through 3.2.0 contain a stored cross‑site scripting flaw in the administration panel's log viewer. A remote, unauthenticated attacker can submit a failed login with a crafted username that is written to the error log. When an administrator opens the log viewer, the embedded JavaScript executes in the administrator's browser, allowing the attacker to perform actions with the administrator's privileges, such as creating new accounts or executing arbitrary code on the server.
Affected Systems
The vulnerability affects Rejetto HFS package versions 3.0.0 through 3.2.0. Users who are running any of these capability should consider themselves at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, but the potential to run code in an administrator's session increases the practical risk. Based on the description, it is inferred that an attacker could send an unauthenticated POST request with a crafted login attempt; the exploitation does not require an attacker‑controlled browser prior to the log view. This inference is drawn from the statement that the scripted code is executed when an administrator opens the log viewer. The EPSS score is < 1% and this vulnerability is not listed in the CISA KEV catalog, yet the ability to privilege‑escalate remains a high‑consequence outcome for environments where administrators routinely review logs.
OpenCVE Enrichment