Impact
Ech0 before version 4.7.3 contains a stored cross‑site scripting flaw in the public RSS feed. Tag names and markdown content are rendered without escaping, allowing an attacker with admin rights to inject JavaScript or malformed HTML into content that is later delivered to RSS readers.
Affected Systems
Ech0’s Ech0 application, versions earlier than 4.7.3 are vulnerable.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. Exploitation requires an adversary to have administrative privileges in order to inject malicious tag names or raw HTML. Once injected, the script executes in any RSS reader that renders the feed, affecting anonymous subscribers and other users who consume the feed. No exploit probability score is available and the vulnerability is not yet listed in CISA’s KEV catalog.
OpenCVE Enrichment