Impact
The vulnerability permits an attacker who can alter cloud resource tags to inject malicious HTML or JavaScript. Those tags are inserted into Prowler’s HTML reports without proper escaping, so opening the report executes the injected code in the victim’s browser. This results in a stored cross‑site scripting flaw (CWE‑79) that can subvert the confidentiality, integrity, or availability of users who view the report.
Affected Systems
Any instance of Prowler Cloud’s Prowler platform running a version earlier than 5.37.0 is affected. Version 5.37.0 and higher incorporate the fix described in the referenced commit, eliminating the unescaped tag insertion.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Because an EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of exploitation remains uncertain. The likely attack vector requires an attacker to have the privilege to add or modify resource tags on scanned resources; once the tags are altered, generating a report that is subsequently opened by another user enables the execution of the injected code.
OpenCVE Enrichment