Impact
The Access Control System (GKS) improperly neutralizes user‑controlled data that is rendered in web pages, creating a reflected cross‑site scripting condition. When a malicious payload is supplied in an HTTP request, the application echoes the data back into a page and the browser executes the script in the victim’s context.
Affected Systems
Armiya Information Technologies Ltd. Co.’s Access Control System (GKS) versions prior to 2.0 are affected. Deployment of these releases exposes the vulnerable input handling logic and can be exploited by any user who can submit requests to the web interface.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The flaw can be triggered by sending a crafted HTTP request from a client browser that includes malicious payloads, which are then reflected back into the page. Based on the description, it is inferred that the attack vector is a client‑initiated HTTP request that the application processes without proper sanitization. No confirmed exploitation has been reported, but because the vulnerability permits arbitrary client‑side code execution, it remains a relevant risk.
OpenCVE Enrichment