Impact
Bacularis versions 1.0.0 through 6.5.0 contain a stored cross‑site scripting flaw in the client address field. Malicious script content supplied by an attacker that is persisted and subsequently displayed to users will be executed within their browser context, allowing the injection of arbitrary code into the page rendering the stored data.
Affected Systems
Bacularis 1.0.0 to 6.5.0 are affected; no additional vendor or product information is provided in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, placing it in the medium severity range, and its EPSS score is listed as less than 1 %, indicating a low likelihood of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a user‑controlled input field: an attacker who can supply or modify the client address field can embed arbitrary JavaScript, which will execute whenever the data is rendered in a browser.
OpenCVE Enrichment