Impact
A vulnerability in the Stats Generation component of stilleshan ServerStatus 1.0 and 2.0 allows an attacker to inject malicious code by manipulating the "custom" argument in server/src/main.cpp. The input is reflected without proper sanitisation, producing a reflected cross‑site scripting flaw that can be triggered remotely. An adversary delivering a crafted request can cause victim browsers to execute arbitrary JavaScript, potentially hijacking sessions or exfiltrating data.
Affected Systems
stilleshan ServerStatus version 1.0 and 2.0 are affected. The flaw resides solely in the Stats Generation module of these releases; no other versions or components are currently known to be impacted.
Risk and Exploitability
The vulnerability has a CVSS base score of 5.1, signalling moderate severity. EPSS is < 1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can target any exposed instance that accepts the "custom" parameter, and may remotely inject scripts that execute in the context of end‑user browsers.
OpenCVE Enrichment