Impact
The vulnerability is an improper neutralization of user‑supplied input in web page generation, allowing cross‑site scripting through HTML attribute injection. This weakness can let an attacker embed malicious scripts or modify page content. It is a type of XSS flaw classified as CWE‑79.
Affected Systems
The affected product is Enocta Educational Technologies Inc.’s Enocta Platform, all releases up to 2026‑09‑28. No specific sub‑components are identified, and the vendor does not list separate version numbers for the affected modules.
Risk and Exploitability
The CVSS score of 4.1 indicates a moderate impact, and the absence of an EPSS score leaves the exact likelihood uncertain. Because the flaw arises from un‑sanitized input, an attacker could exploit it by crafting a malicious payload in a URL or form field accessible to end‑users. No entry in the CISA KEV catalog suggests public exploitation is not yet documented, but the web‑based nature of the flaw warrants prompt attention.
OpenCVE Enrichment