Impact
Jet Admin is vulnerable to a stored cross‑site scripting flaw that allows an authenticated attacker to inject arbitrary JavaScript through the sign‑in page’s Scripts and Styles option. The injected code is executed in the browser context of any user who visits the sign‑in page, giving the attacker the ability to steal cookies, hijack sessions, or otherwise corrupt data. The weakness is a classic example of input validation failure (CWE‑79), which can lead to significant confidentiality, integrity, and availability violations.
Affected Systems
The vulnerability affects the Jet Admin product, Jet Admin. No specific version information is provided, so all versions currently deployed are potentially impacted until a vendor fix is released.
Risk and Exploitability
With a CVSS score of 8.5, the flaw is considered high severity. The attack requires the attacker to be authenticated to the application, indicating that it is typically a threat from insiders or compromised accounts. Because the vulnerability is stored, the malicious script can persist across sessions and affect every user who visits the sign‑in page, increasing the potential impact. The EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, but the high CVSS and the fact that it affects all users inside the application make it a serious risk for organizations using Jet Admin.
OpenCVE Enrichment