Impact
SpiderFoot does not escape correlation titles that are constructed from data received from external scan sources such as server banners and metadata. An attacker can embed malicious HTML elements with event handlers into these titles. When a user opens the correlations view in a browser, the injected scripts run in the context of the operator and can exfiltrate sensitive information like API keys. This constitutes a high‑impact client‑side code execution vulnerability.
Affected Systems
The vulnerability affects all installed instances of SpiderFoot provided by the vendor smicallef. No specific patches or version numbers are listed in the current data, so all currently supported releases are potentially affected until a remediation is applied.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. No EPSS score is available, but the lack of KEV listing suggests no known widespread exploitation yet. The feasible attack vector is the injection of crafted data into the correlation titles through external scan feeds; an attacker would need to supply such data, which is then displayed when the operators view the correlations page. If successful, the script would execute in the operator’s browser and allow exfiltration of API keys or other credentials stored locally.
OpenCVE Enrichment