Impact
The vulnerability exists in Grav Shortcode Core versions prior to 6.2.5. The [lorem] tag parameter and the [details] tag summary field are written directly into rendered pages without escaping. An attacker who can edit a page can inject arbitrary HTML or JavaScript that will be executed in the browsers of all page visitors, including administrators. This results in the ability to run client‑side code that could steal session tokens, deface pages, or perform other malicious actions.
Affected Systems
GetGrav Grav Shortcode Core versions below 6.2.5, including 6.2.4 and any earlier releases.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk. Because exploit code is stored in the content, it requires the attacker to have page‑edit privileges. No exploits have been reported in the CISA KEV catalogue and no EPSS score is available. Attackers with editing rights can create a stored payload that will run in every visitor’s browser; the risk therefore scales with the number of users who view the affected page.
OpenCVE Enrichment