Impact
A cross‑site scripting flaw exists in the Query Console of Progress MarkLogic Server that enables a remote attacker to inject and run arbitrary JavaScript in the browser session of an authenticated administrator. Because the code runs with the administrator’s privileges, the attacker can harvest stored credentials and perform privileged actions on the system. The weakness corresponds to CWE‑79, a typical XSS vulnerability, and is amplified by path traversal handling (CWE‑22).
Affected Systems
The vulnerability affects versions of Progress MarkLogic Server prior to 11.3.6 and 12.0.3; these versions expose the Query Console component on the App‑Services port (8000).
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity risk. Although the EPSS score is not available, the vulnerability requires an authenticated administrator and luring them to a crafted URL, suggesting that exploitation is possible in environments with exposed Query Console access. The vulnerability is not listed in the CISA KEV catalog, but its impact can allow credential compromise and unauthorized actions if an administrator clicks a malicious link. The attack vector is inferred to be a web‑based lure that the attacker delivers to the authenticated user.
OpenCVE Enrichment