Impact
The vulnerability is a stored cross‑site scripting flaw (CWE‑79) that allows untrusted input to be rendered as executable scripts within the e‑Logo Purchasing Portal. This flaw means that an attacker can inject malicious JavaScript that will run in the browsers of any user who views the affected page, potentially leading to session hijacking, credential theft, or data disclosure.
Affected Systems
Affected systems are Logo Software Industry and Trade Inc.’s e‑Logo Purchasing Portal versions prior to 1.52. No specific build or platform limitations are listed, so all deployments of the portal before the 1.52 release are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. Because the exploit is stored in the web application and does not require privileged access, the risk is that any user with access to the portal can become a vector for the attacker's payload. The EPSS score is not provided, and KEV is not listed, so no large‑scale exploitation evidence is available. Nonetheless, the lack of input sanitization makes this issue relatively easy to exploit through common web forms or administrative interfaces.
OpenCVE Enrichment