Impact
The vulnerability allows attackers to inject client-side scripts into a webpage through improper neutralization of user-supplied input, a reflected XSS flaw classified as CWE-79.
Affected Systems
Vendor Tangible:Loops & Logic offers the Loops & Logic plugin. No specific affected versions were provided in the data, so all current or legacy releases may be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not currently documented. Likely attack vectors involve crafted URLs or form inputs delivered to users that subsequently render unsanitized data.
OpenCVE Enrichment