Impact
The vulnerability is a stored cross‑site scripting flaw in Flextype CMS versions 0.9.9 through 1.0.0‑alpha.3. Due to insufficient HTML escaping of plugin directory names, an attacker who can write to the plugins directory can create a plugin whose name contains malicious scripts. plugin dependency, it renders a raw directory name, causing the browser to execute the attacker‑supplied code. This results in arbitrary script execution in the browsers of users who view the error page, potentially enabling session hijacking or other client‑side attacks. The flaw represents a client‑side injection weakness identified as CWE‑79.
Affected Systems
Flextype CMS versions 0.9.9 through 1.0.0‑alpha.3 hosted on any web server environment that permits users to write to the files or directories used for plugins. The flaw is present wherever the getValidPluginsDependencies() function runs and renders an unescaped dependency error. All installations of Flextype CMS containing the vulnerable code are affected, regardless of the presence of other plugins.
Risk and Exploitability
The CVSS score of 2.4 indicates low severity. No EPSS score is provided, so the current exploitation probability is unknown but likely limited to environments where an attacker has file‑write access to the plugins directory. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires the ability to create or rename a plugin directory so that the dependency validation error occurs; this usually means the attacker needs administrative or privileged access to the file system. Therefore, while the technical impact is low, the risk rises if reasonable safeguards for plugin directory write permissions are not in place.
OpenCVE Enrichment