Impact
The vulnerability lies in the order‑print.jsp file of the Exrick xmall manager‑web component where user input is reflected Attackers can craft a malicious request that injects JavaScript into the print order page, allowing the execution of arbitrary client‑side code in the context of a logged‑in manager session. This reflected XSS can lead to session hijacking, credential theft, and unauthorized access to sensitive order data. The weakness is mapped to CWE‑79 for reflected XSS and CWE‑94 for unsafe evaluation of user data.
Affected Systems
The affected product is Exrick xmall. No specific version numbers are supplied; the last known vulnerable state is commit 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Because the project follows a rolling‑release model, newer releases may already contain a fix, but no official patch has been released yet.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of < 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog, leaving the overall risk moderate. Attackers can remotely exploit the flaw through the web interface by submitting crafted order‑printing requests, and any compromised user session will be vulnerable until a patch or mitigation is applied.
OpenCVE Enrichment