Impact
Unblu Spark has an open‑redirect flaw that can be leveraged to inject and execute arbitrary JavaScript in the victim’s browser. Because the redirect is uncontrolled, an attacker can craft a URL that loads a malicious script, leading to a DOM‑based cross‑site scripting condition. In deployments where the application runs with com.unblu.identifier.siteEmbeddedSetup=true, the script inherits the host application’s origin; this grants the attacker full access to the host’s cookies, DOM, and same‑origin APIs, broadening the blast radius beyond Unblu Spark alone.
Affected Systems
The affected product is Unblu Spark from Unblu Inc. No specific vulnerable versions are listed in the advisory, but the remediation note refers to earlier versions. The workaround applies only to Unblu Spark 7.56.2 and later in the 7.x series and 8.19.1 and later in the 8.x series. All other versions may remain vulnerable until patched.
Risk and Exploitability
The CVSS score is 7, indicating a high‑severity issue; the EPSS score is 0.00244, which is less than 1% and indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to supply a malicious redirect URL, which can be triggered by sending a crafted link to a user or embedding it in content. When the application is configured with the siteEmbeddedSetup flag, the attack is more dangerous because the injected script runs with the host application’s credentials, potentially compromising the entire host environment.
OpenCVE Enrichment