Impact
A client‑side cross‑site scripting flaw exists in the utils.toToc function of ArticleController.java in maliangnansheng bbs‑springboot. Input is not properly encoded, allowing an attacker to inject scripts that execute in users’ browsers when the page is rendered. This enables arbitrary client‑side code execution. The assessment is based solely on the provided description; no additional exploitation consequences are specified.
Affected Systems
The flaw exists in maliangnansheng bbs‑springboot version 3.0.0. No other vendor or product variants or version ranges are indicated in the available data.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level. The EPSS score of < 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw remotely by supplying crafted input to the utils.toToc endpoint; no special privileges or local access are required.
OpenCVE Enrichment