Impact
The vulnerability in bizwell xClick arises from improper validation of user input, allowing an attacker to embed malicious scripts that are stored within the application. When a victim accesses the affected page, the script executes in their browser, which can lead to theft of session cookies, authentication tokens, or other sensitive data, and may also be used for defacement or phishing. The weakness is a CWE-20 input validation flaw.
Affected Systems
The affected product is bizwell xClick. Versions R2, R3, and R3.1 are impacted. Users on these releases should verify their current version and consider applying available updates.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score is less than 1%, implying a low exploitation probability at present; however, the vulnerability remains present and could still be abused by attackers who craft malicious user input that is stored by the system. The flaw is not listed in the CISA KEV catalog, so no large‑scale exploits have been reported yet. Attackers can inject scripts into user‑generated content; when other users view this content, the injected scripts execute in their browsers, potentially stealing cookies, tokens, or user data.
OpenCVE Enrichment