Impact
The vulnerability is a reflected cross‑site scripting flaw located in the StartPAOSResponse handler of Governikus AusweisApp. An attacker can manipulate the ResultMessage argument, causing the application to render and execute arbitrary HTML or JavaScript in the victim’s browser. This can lead to session hijacking, credential theft, or malicious content injection, exploiting conventional input validation weaknesses (CWE‑79) and potential dynamic code evaluation (CWE‑94).
Affected Systems
Governikus AusweisApp versions up to and including 2.5.4 are affected. The flaw resides in the StartPAOSResponse handler component; upgrading to version 2.5.5 or later removes the weakness.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote, as a client‑side attacker can supply a crafted ResultMessage to a user running the application, resulting in reflected XSS in a browser or web view component.
OpenCVE Enrichment