Impact
Improper neutralization of script‑related HTML tags allows basic stored XSS. An attacker can submit malicious HTML or JavaScript that is then rendered for all users, potentially enabling credential theft, defacement, or session hijack. The vulnerability is classified as a basic XSS (CWE‑80).
Affected Systems
İzometri IT Services Domestic and Foreign Trade Co. Ltd. product eimzamip is affected. Versions from 1.6.4 through 1.6.6 (inclusive) are vulnerable; versions 1.6.7 and later contain the fix.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires the ability to submit data that is stored and later rendered on a web page; no privilege escalation or remote code execution is provided.
OpenCVE Enrichment