Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the web page output of Bifra Engineering Consulting Ltd.'s Q‑smart NexT Poll application. When users submit data that is not properly neutralised, the data is saved and later rendered to other users, enabling the execution of arbitrary scripts in the victim’s browser. This can lead to credential theft, session hijacking, defacement, or the delivery of additional malware. The weakness is classified as CWE‑79, a typical input‑validation issue.
Affected Systems
The flaw exists in Bifra Engineering Consulting Ltd.'s Q‑smart NexT Poll prior to version 1.8.7. It affects any deployment of that product regardless of the host environment, as the vulnerability is triggered by user‑supplied input fields in the poll creation or response interfaces. No other vendors or product versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity with a medium likelihood of exploitation under the conditions described. EPSS score is 0.00162 (< 1%), reflecting a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, implying no known large‑scale exploitation. The most likely attack vector is via a legitimate user interface where the attacker supplies malicious payloads that are stored. Successful exploitation requires that the attacker can submit data to the application, but no elevated privileges are required. Consequently, all users who can view the poll outputs are at risk.
OpenCVE Enrichment