Impact
Network administrators should be aware that kkFileView versions 5.0.0 through 5.0.2 are vulnerable to a reflected cross‑site scripting flaw. The OnlinePreviewController forwards user‑supplied "page" and "kkagent" query parameters straight to FreeMarker templates without any sanitization, and the templates embed those values directly into raw JavaScript contexts. This omission allows an attacker to inject arbitrary client‑side code, leading to the execution of malicious scripts in the context of anyone who visits the crafted URL. The weakness corresponds to CWE‑79, which represents improper neutralization of input during web‑page generation.
Affected Systems
The affected product is kkFileView, a file‑viewer component used in internal web portals. Any deployment running versions 5.0.0, 5.0.1, or 5.0.2 with the /onlinePreview endpoint enabled is susceptible. No specific vendor or further product line is mentioned; it is inferred that the issue likely exists system‑wide for those versions.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. The nominal EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalogue, suggesting that active exploitation is currently unlikely. Nevertheless, the flaw can be exploited manually by placing a malicious payload in the 'page' or 'kkagent' parameters of a URL (e.g., /onlinePreview?page=...&kkagent=...). Based on the description, it is inferred that the likely attack vector involves embedding malicious payloads into these parameters to trigger script execution. Because the payload is reflected back into a JavaScript context, any user who loads the URL will have the script executed in their browser. Attacks could range from cookie theft to session hijacking or more complex phishing interactions, with impact confined to the victim’s session but potentially affecting sensitive data accessed through kkFileView.
OpenCVE Enrichment