Impact
The vulnerability resides in the Form Write View component of TDuckApp tduck-platform, specifically the submitShowCustomPageContent argument in the index.vue file. An attacker can supply crafted content that is interpreted as JavaScript, leading to a stored or reflected cross‑site scripting flaw. The injected code executes within the victim’s browser context, enabling attackers to steal session cookies, deface content, or perform further malicious actions. The weakness is catalogued as CWE‑79 and CWE‑94, indicating unchecked code injection and potential for arbitrary script execution.
Affected Systems
TDuckApp tduck-platform versions through 5.3 are affected. Any deployment running these releases is vulnerable, and the vendor has not yet released a patch or advisory to address the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1 % reflects a very low but non‑zero chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation can be achieved remotely by sending a specially crafted request to the application without requiring any elevated privileges, making it easily reachable for attackers.
OpenCVE Enrichment