Impact
A cross‑site scripting flaw exists in the JSON‑LD Theme component of GEOFlow, caused by untrusted handling of the Search argument within HomeController.php. This flaw allows a remote attacker to inject malicious scripts that will execute in the browsers of users who view the affected page, thereby opening a vector for executing code in the client context. The vulnerability is identified by CWE‑79 and potentially involves code execution within the browser context, as indicated by the presence of CWE‑94.
Affected Systems
All installations of yaojingang GEOFlow version 2.1.0 or earlier are affected. Deployments of version 2.1.1, released with the patch commit 67abfd864a15d169a78429f3290c91cb3b93e849, eliminate the vulnerable code path.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. No EPSS score is available, so the current exploitation probability is unknown, and the flaw is not listed in the CISA KEV catalog. The attack can be carried out remotely via normal web traffic, and the publicly disclosed exploit demonstrates that an attacker can leverage the vulnerability against vulnerable deployments.
OpenCVE Enrichment