Impact
Incorrect order of validation and canonicalization in Pentestify’s report theme CSS sanitizer allows a malicious user to inject CSS hex escapes that reconstruct the url() function and bypass the blocklist. The attacker can force victims’ browsers to send outbound HTTP requests to arbitrary sites, thereby exposing the victim’s IP address and User‑Agent string. The vulnerability does not grant code execution or privilege escalation but enables a form of client‑side request smuggling that can leak user identity and be used for phishing or other social‑engineering attacks.
Affected Systems
Vendor maalfer’s Pentestify product, versions 1.2.0 through 2.3.2 (excluding 1.1.1) are affected. The fix has not been released as a tagged update, but the recommended approach is to install the latest code from the repository, which contains the patched sanitizer. The affected releases shipped with vulnerability because of a missing version bump, so the upper bound cannot be stated until a new release is issued.
Risk and Exploitability
The CVSS score of 5.1 reflects moderate severity. EPSS score 0.00289 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower likelihood of already exploited attacks. Exploitation requires an authenticated user able to create or modify report themes, and a victim who views a report containing the malicious CSS. While the attack surface is limited to users who load such themes, the data disclosed (IP address and User‑Agent) can still be valuable to adversaries. Overall, the risk is moderate, and immediate remediation is advisable once a patched version becomes available.
OpenCVE Enrichment