Impact
Heptabase contains an authenticated stored cross‑site scripting flaw that allows remote attackers to embed malicious JavaScript into specific pages. The injected payload is persisted on the server and executes in the victim’s browser whenever the crafted content is accessed or clicked, enabling arbitrary client‑side code execution, credential theft, or phishing.
Affected Systems
Hepta Platforms’ Heptabase platform is affected. All releases prior to 1.93.1 carry the vulnerability, as the vendor recommends upgrading past that version to fix the flaw.
Risk and Exploitability
The vulnerability scores a CVSS base of 6.2, indicating moderate severity. EPSS information is not available, and the flaw is not listed in CISA’s KEV catalog. Because it requires authenticated access, exploitation demands attacker credentials; therefore the attack surface is limited to insiders or compromised accounts. Nonetheless, once proven, the stored payload can compromise a broad user base.
OpenCVE Enrichment