Impact
Flowintel renders calendar event titles with innerHTML, using data derived from case titles. A user capable of creating or editing a case title can inject HTML or script that is stored and later interpreted by browsers when another user views the calendar, resulting in stored cross‑site scripting. The flaw is a classic input‑validation weakness identified as CWE‑79.
Affected Systems
The affected product is Flowintel. Version 3.3.0 is impacted; later releases are presumed fixed unless otherwise noted.
Risk and Exploitability
With a CVSS score of 5.1 the vulnerability is of moderate severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user with permission to modify case titles, which then targets other authenticated users who view the calendar. The risk is confined to web browsers entering the calendar view and does not provide remote code execution beyond the user’s session context.
OpenCVE Enrichment