Impact
A reflected cross‑site scripting flaw resides in the grid_datasource.php component of AppNitro MachForm v30. By supplying a malicious payload in the filter[filters][0][field] parameter, an attacker can cause the application to echo the value back to the browser, where it is executed as JavaScript. Such execution permits session hijacking, credential theft, defacement, or the launch of additional malicious code. The weakness maps to CWE‑79.
Affected Systems
Only AppNitro MachForm version 30 is affected; no other vendors or product lines are implicated in the advisory.
Risk and Exploitability
The vulnerability does not require authentication or privileged access; any user who visits a crafted URL or submits a malicious form can trigger it. The likely attack vector depends on user interaction, making phishing or compromised sites common delivery methods. The EPSS score is < 1% and the flaw is not listed in the CISA KEV catalog, yet the combination of ease of exploitation and potential for significant impact keeps the overall risk high for any site running the vulnerable application.
OpenCVE Enrichment