Impact
The vulnerability is an improper neutralization of user‑supplied input during web page generation, allowing a reflected Cross‑Site Scripting flaw. This flaw enables an attacker to inject malicious scripts that are executed in the victim’s browser when the page is viewed.
Affected Systems
The flaw exists in IdeaSoft Software Industry and Trade Inc.'s Smart E‑Commerce product in any release before version 8.4.2.0. No other versions or products are listed as affected in the CVE data.
Risk and Exploitability
The CVSS v3.1 score of 6.1 indicates moderate severity. The EPSS score below 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are known. The likely attack vector would involve enticing a user to a crafted URL or form that contains unsanitized input which the server echoes back. Based on the description, it is inferred that an attacker would need to lure a victim to view a page containing malicious scripts to trigger the flaw.
OpenCVE Enrichment