Impact
A reflected cross‑site scripting flaw exists in x‑ui version 0.3.2. The management interface reflects the raw request URI directly into a client‑side template binding expression that highlights the sidebar menu. Server‑side HTML entity escaping does not protect this context because the browser decodes entities before the expression is evaluated as JavaScript. An attacker can craft a URL that, when opened by a logged‑in panel user, causes the browser to execute arbitrary JavaScript in the same‑origin context of the management page, enabling the theft of session data and malicious actions performed under the victim’s credentials.
Affected Systems
The affected product is the open‑source web management interface x‑ui, version 0.3.2. No additional vendor or product details are listed. The vulnerability applies to any deployment of this specific version that exposes the management interface to authenticated users.
Risk and Exploitability
Severity is not quantified in the available CVSS metrics, but the impact of arbitrary client‑side script execution in a trusted session is high. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of observed exploitation is unknown. The attack requires an authenticated user to click a crafted link, so an attacker could trigger the flaw by luring a legitimate panel administrator to a malicious URL. Once executed, the script runs with the permissions of the logged‑in user, allowing data exfiltration or unauthorized actions within the application.
OpenCVE Enrichment