Impact
A stored cross‑site scripting vulnerability exists in the profile management component of T‑Systems TAO 2.0. An authenticated user can inject malicious HTML or JavaScript into their personal data fields. The application then stores and renders this content without sanitisation whenever another user, including administrators, views the profile, which can lead to arbitrary script execution in the victim’s browser, exposure of session data, or the execution of actions with the victim’s privileges.
Affected Systems
All installations of T‑Systems TAO 2.0 are affected, including the default 2.0 release running on any supported platform. The vulnerability was fixed in release 2602.0.0; upgrading to that version or later removes the flaw.
Risk and Exploitability
The CVSS score is 5.1, indicating a moderate severity, while the EPSS score is below 1 %, suggesting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalogue. Exploitation requires a legitimate authenticated account to create the malicious content, followed by another user viewing the edited profile. Once this sequence is achieved, the attacker can run JavaScript in the victim’s browser and potentially hijack the session or perform privileged actions on behalf of the victim.
OpenCVE Enrichment