Impact
Bacularis from version 4.7.0 through 6.5.0 allows stored XSS through director tags, a form of input that can contain arbitrary HTML or JavaScript. The flaw permits an attacker to embed malicious scripts that will be served to any user who views a page containing the tag, potentially exposing user session data or enabling further exploitation and can compromise confidentiality and integrity of user data via script execution in victims’ browsers.
Affected Systems
All instances of Bacularis with firmware versions 4.7.0 through 6.5.0 are affected. Users of earlier or newer releases are not impacted by this specific issue.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV. The CVSS score is 6.1, but stored XSS generally poses a high risk when the component is exposed to untrusted input. Based on the description, the likely attack vector is inferred as the submission of director tag data by an authenticated or unauthenticated user with write permissions. Successful exploitation would enable the execution of arbitrary client‑side code in the context of the victim’s browser. The overall risk depends on the exposure of the director tag interface and the user population that can view it.
OpenCVE Enrichment