Impact
The vulnerability arises from improper neutralization of user‑supplied input during web page generation, allowing malicious scripts to be injected and executed in the browsers of other users who view the affected pages. This can lead to credential theft, session hijacking, or defacement of the application.
Affected Systems
The flaw exists in the CAPEC‑63 component, affecting all releases prior to version 3.0b63. No other vendors or products are explicitly listed, so any deployment of CAPEC‑63 before that version remains vulnerable.
Risk and Exploitability
With a CVSS score of 5.8, the vulnerability has moderate severity. The EPSS score is not available and it is not listed in CISA’s KEV catalog, so the current exploit probability is unclear. The likely attack vector involves an attacker sending crafted input—such as a URL parameter or form field—to the affected application, which then reflects unsanitized data back to users, enabling Cross‑Site Scripting attacks.
OpenCVE Enrichment