Impact
The vulnerability is a reflected cross‑site scripting flaw where the plugin echoes UTM query parameters into form HTML without escaping. An attacker can craft a URL containing a malicious script within a UTM parameter. When a victim visits the URL, the script executes in the victim's browser, potentially allowing session hijacking, data theft, or defacement. The flaw is unauthenticated, meaning anyone can trigger it by visiting the URL.
Affected Systems
This flaw affects the Brave Popup Builder plugin with any version earlier than 0.8.6. The affected package is listed in the plugin directory under Unknown:Brave. No other vendors are explicitly known. The vulnerability is present in version 0.8.5 or earlier.
Risk and Exploitability
Because the exploit requires only a crafted URL and does not need privileged access, the potential impact is high. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, indicating no public exploitation at the time of analysis. Nevertheless, reflected XSS poses a significant risk, especially on sites that allow users to embed content. Attackers could inject arbitrary JavaScript, and the lack of mitigations makes exploitation straightforward.
OpenCVE Enrichment