Impact
This vulnerability resides in add_task.php, allowing an attacker to supply a crafted og_objects.name argument that the system outputs without adequate sanitization. The flaw enables the injection of arbitrary JavaScript code into the page context, granting an attacker the ability to steal session cookies, execute malicious actions on behalf of logged‑in users, or deface the application interface. The error does not provide direct code execution on the server, but the XSS payload can be delivered remotely and leveraged against any authenticated or unauthenticated user visiting the affected page.
Affected Systems
The issue affects the Feng Office product from Fengoffice. All releases of Feng Office up to version 3.11.13.11 are vulnerable. No official patch version is listed, so users should seek later releases or vendor‑issued fixes that address this flaw.
Risk and Exploitability
The CVSS score of 5.1 classifies the vulnerability as Medium severity. The EPSS score of < 1% indicates a low exploitation probability, and the flaw is not included in the CISA KEV catalog, suggesting that exploitation may not yet be widespread. However, the vulnerability is publicly disclosed, and the remote attack vector allows anyone to craft malicious input. Because the flaw relies on user‑controlled data being reflected unencoded, automated or targeted scripts can deliver attacks against any user visiting the affected page. System administrators should verify whether a newer release or patch is available and consider mitigating the vulnerability until a fix is applied.
OpenCVE Enrichment