Impact
This vulnerability is a stored cross‑site scripting flaw that allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and cust_locate. The inputs are saved without HTML encoding and are rendered unescaped in profile views that are visible to administrators. By crafting an appropriate payload, an attacker can cause the JavaScript to run in an administrator’s browser session, potentially enabling session hijacking or privilege escalation.
Affected Systems
Affected products are ElkArte Forum, specifically the ElkArte 2.0 Beta 1 release. No other versions were identified as impacted by the current data.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating a moderate severity. Exploitation requires only that the attacker be a registered user able to edit the two profile fields, after which the malicious code executes when an administrator views the profile. Because the code runs in the administrator’s browser context, it can hijack the admin session or elevate privileges. The EPSS score is not available, so the probability of exploitation is uncertain, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment