Impact
The Access Control System (GKS) exposes a basic cross-site scripting flaw caused by an improper neutralization of script-related HTML tags. Attackers can inject arbitrary HTML or JavaScript into rendered pages, specifically targeting HTML attributes, which may lead to client-side code execution.
Affected Systems
All releases of Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 are affected.
Risk and Exploitability
The flaw carries a CVSS score of 6.1, indicating moderate severity, and an EPSS score of less than 1%, pointing to a very low yet non-zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector likely involves an attacker supplying a malicious payload through user-controlled content that the application reflects in a browser, such as a crafted link or form submission, resulting in client-side code execution.
OpenCVE Enrichment