Impact
The vulnerability is an unvalidated Cross‑Site Scripting flaw in SOY Gallery that allows an attacker to inject and execute arbitrary JavaScript in the web browser of any user who logs into the product. This can lead to data theft, session hijacking, or malicious content injection from the victim’s perspective.
Affected Systems
The flaw affects the SOY Gallery application developed by Tsuyoshi Saito. No specific affected versions are listed in the advisory, so all releases of the product remain potentially vulnerable until a patch is applied.
Risk and Exploitability
The issue carries a CVSS score of 4.8, indicating a moderate impact. EPSS data is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is remote via the web, with the attacker needing to lure a logged‑in user into the vulnerable portion of the application.
OpenCVE Enrichment