Impact
The vulnerability occurs when the AIL Framework stores a crawler URL directly within a JavaScript onclick handler for displaying a screenshot, without proper encoding. The stored URL can contain JavaScript syntax, which is injected into the browser context of a logged‑in analyst. When the analyst clicks the screenshot icon, the malicious code executes in the analyst’s browser within the security context of the AIL Framework application. This can expose session data, modify displayed content, or perform privileged actions under the analyst’s rights.
Affected Systems
The affected product is the AIL Framework (ail-project:ail-framework). Specific affected versions are not enumerated in the public data; therefore any install that contains the unpatched crawler domain view is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity for this stored XSS flaw. No EPSS score is available, so the likelihood of exploitation cannot be quantified from publicly known data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to influence the crawler to record a malicious URL, and a victim must then click the screenshot link while authenticated. The lack of an available EPSS score and KEV listing suggests that, while the flaw is significant, it may not be widely exploited at present. However, because the impact occurs in the authenticated user’s browser, the attack surface is significant for organizations using the AIL Framework.
OpenCVE Enrichment