Impact
Improper neutralization of user input during web page generation in the Apache SkyWalking Booster UI dashboard widgets leads to stored cross‑site scripting. When malicious content is persisted within widget configuration data, it is later rendered to other users’ browsers, resulting in the execution of arbitrary client‑side code. This flaw directly corresponds to the CWE‑79 weakness and can enable attackers to run scripts in the context of users interacting with the dashboard.
Affected Systems
The vulnerability affects Apache SkyWalking UI versions 10.2.0 through 10.4.0, shipped by the Apache Software Foundation. It relates specifically to the dashboard’s widget configuration and rendering components. The vendor recommends upgrading to Horizon UI 1.0.0 to eliminate the flaw.
Risk and Exploitability
The CVSS score is 6.1, the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalogue. The flaw can be triggered by any user who can inject data into widget configurations, or by a remote attacker if the UI is exposed. The risk is moderate, but the potential impact on the user’s browser remains significant. Prompt remediation is recommended to mitigate any exploitation risk.
OpenCVE Enrichment