Impact
The vulnerability is a stored cross‑site scripting flaw in Froiden TableTrack’s order notes field. The application does not sanitize user‑supplied input, allowing an attacker to embed arbitrary HTML or JavaScript. An unauthenticated user can submit an order populated with a malicious payload; the payload is persisted and later rendered in the administrator’s browser when the order is viewed. If exploited, the attacker can steal session cookies, hijack the admin session, or perform unauthorized administrative actions.
Affected Systems
Froiden TableTrack version 1.3.10 and earlier are affected. The flaw resides in the order‑management component of the restaurant‑management solution provided by Froiden. As long as the order notes field remains unfiltered, any installation of these releases remains vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 classifies this as a medium‑severity vulnerability. An attacker only needs to craft a single order with a malicious note; authentication is not required to create the order, but exploitation requires an administrator to open the order’s details in a browser. The EPSS score of < 1 % indicates a very low likelihood of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Still, because the vector is trivial and the impact on an admin session can be significant, caution is advised.
OpenCVE Enrichment