Impact
A reflected cross‑site scripting flaw exists in the editormd.js file used by the API Page Save endpoint of star7th Showdoc up to version 3.9.1. The vulnerability allows an attacker to craft a request that causes malicious JavaScript to be executed in the browser context of users viewing the affected page. The impact is the injection of arbitrary client‑side code, potentially enabling credential theft, session hijack or defacement. This weakness is documented as CWE‑79 (XSS) and CWE‑94 (Code Injection) and can be exploited remotely, as the description states the attack may be launched remotely and an exploit has been publicly disclosed.
Affected Systems
Vendor star7th produces the Showdoc product. Versions up to and including 3.9.1 are affected. The fix is available in version 3.9.2, identified by commit a8ea1520850b4242f395247f72e87e597506cef0.
Risk and Exploitability
The CVSS score of 5.1 marks the vulnerability as moderate severity, yet the EPSS score is not available and it is not listed in the CISA KEV catalog. The publicly disclosed exploit indicates that attackers can trigger the flaw by manipulating the API Page Save request from an external source. Since the vulnerability is remote and does not provide remote code execution on the server, the risk is contained to client‑side execution, but the availability of a public exploit raises the likelihood of real‑world exploitation.
OpenCVE Enrichment