Impact
Improper neutralization of user input during web page generation creates a Stored Cross‑Site Scripting flaw. The weakness, identified as CWE‑79, allows an attacker to embed malicious scripts that are later executed in other users’ browsers when the stored data is viewed. This can lead to execution of arbitrary JavaScript in the victim’s browser, potentially exposing sensitive information or performing unauthorized actions. The specific outcomes depend on the stored context and victim interaction, but any execution in a user's browser could compromise their session or data.
Affected Systems
Armiya Information Technologies Ltd. Co. Access Control System (GKS) versions prior to 2 are affected.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, while the EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves web input fields that accept and store arbitrary data for later display without proper encoding, enabling an attacker to inject a payload via the application’s input controls that is executed in the browsers of other users who view the stored content.
OpenCVE Enrichment