Impact
The vulnerability is a stored cross‑site scripting flaw that stems from improper neutralization of user input during page generation. This weakness is classified as CWE‑79. Because the application accepts and displays HTML content without adequate sanitization, an attacker can embed malicious scripts that execute in the browsers of any user who views the affected content. This client‑side code execution enables cookie theft, and other user‑level compromises. The description does not detail organization‑wide impact, but typical outcomes of stored XSS include compromise of user accounts and unauthorized data exfiltration.
Affected Systems
DivvyDrive Information Technologies Inc.'s product DivvyDrive is impacted from version 4.8.2.23 through, but not.8.3.1. All releases within that range require remediation. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred to be remote through a web form or API that accepts user content user‑level compromise or credential theft.
OpenCVE Enrichment