Impact
Improper neutralization of user‑supplied data during the generation of web pages results in a reflected cross‑site scripting vulnerability. The flaw allows an attacker to deliver and execute arbitrary JavaScript within the victim’s browser session, potentially exposing or manipulating data displayed by the application, or enabling other client‑side attacks. The weakness is a failure to properly encode output (CWE‑79).
Affected Systems
All releases of Polen Media Software and Information Services’ Website Template before version 2.0 are affected; no additional sub‑version details are provided.
Risk and Exploitability
The vulnerability carries a CVSS base score of 6.1, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires a web request that echoes user data back in the page, so a crafted URL or form field can trigger the reflected XSS. The impact is confined to the victim’s browser and the data rendered by the application in that context.
OpenCVE Enrichment