Impact
A stored XSS flaw exists in the vendor_store_name field of the /administrator/index.php endpoint. An authenticated attacker who can submit a new vendor store name can embed malicious scripts that will be stored in the database and later executed in the browsers of users who view the stored data. The vulnerability does not grant escalation of privileges beyond what the attacker already has; it allows an attacker to inject code for the benefit of other users’ sessions only. The weakness is a classic input‑validation failure identified as CWE‑79.
Affected Systems
The affected software is TPVEnlanube’s Cloud Web application. No specific version numbers are disclosed, but the vulnerability is present in whichever version is running at the time of the advisory. If an administrator is using this application, they are potentially vulnerable.
Risk and Exploitability
The CVSS score is 4.8, indicating a moderate impact. No EPSS value is available, so the probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no evidence of active exploitation yet. The likely attack path requires the attacker to be authenticated as an administrator to be able to submit the malicious vendor_store_name value and have it stored for later viewing by other users.
OpenCVE Enrichment