Impact
MOOS core‑moos through version 10.4.0 does not escape data stored in the MOOS database when rendering its HTTP pages, allowing a malicious publisher to insert script payloads into variable values. When an operator views the affected page in a web browser, the unescaped data is rendered as executable JavaScript, leading to client‑side script execution. The vulnerability may compromise the confidentiality or integrity of information displayed to the operator, as well as the surrounding user interface.
Affected Systems
The affected product is MOOS core‑moos, all releases up to and including 10.4.0. Any deployment that exposes MOOSDB HTTP pages is susceptible if the publisher interface allows variable values to be set by an attacker.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers who can write variable values through the publisher interface—whether locally or over the network—can inject the payload. When an operator accesses the relevant HTTP page, the browser will execute the injected script. The risk is therefore moderate in environments where publisher permissions are not strictly controlled or where the MOOSDB web interface is publicly reachable.
OpenCVE Enrichment