Impact
Improper neutralization of user input during web page generation in the Booster UI dashboard widgets allows a stored cross‑site scripting attack. When a malicious script is persisted in the widget data and later rendered to other users, it executes within the victim’s browser context, granting the attacker the victim’s privileges. This can lead to session hijacking, data theft, defacement, or other malicious actions that require the viewer’s level of access.
Affected Systems
The vulnerability exists in Apache SkyWalking UI versions 10.2.0 through 10.4.0. It is shipped by the Apache Software Foundation and affects the web dashboard’s widget configuration and rendering components. The vendor recommends upgrading to Horizon UI 1.0.0 to eliminate the flaw.
Risk and Exploitability
No CVSS or EPSS score is disclosed and the vulnerability is not listed in the CISA KEV catalogue. However, stored XSS is a well‑known high‑risk weakness that can be triggered by any user who can inject data into widget configurations, or by a remote attacker if the UI is exposed. Until the upgrade to Horizon UI 1.0.0 is performed, the risk of cross‑site script execution remains significant and should be treated as high.
OpenCVE Enrichment