Impact
The vulnerability is a Cross‑Site Scripting flaw caused by improper neutralization of user input during web page generation in Webbeyaz Web Design’s Mediküm Web. Because the input is not properly encoded, an attacker can insert malicious JavaScript that is reflected back to the user in the HTTP response. The injected script runs in the victim’s browser, allowing arbitrary client‑side code to execute.
Affected Systems
Webbeyaz Web Design’s Mediküm Web product, any version up to and including 08072026, is affected. The vendor has indicated the product is no longer supported, so no official patch or update is available.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity level. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to craft a request containing malicious input that is reflected in the page viewed by the victim.
OpenCVE Enrichment