Impact
A flaw was identified in the SearchEngine::buildHighlights method of olivier‑ls PHP‑FTS, where an attacker can manipulate the Query argument to inject malicious script content. This stored cross‑site scripting vulnerability allows the attacker to execute arbitrary JavaScript in the browsers of users who view the affected search results. Based on the description, the attack vector is inferred to involve sending a crafted Query parameter to the search endpoint. The impact is that the attacker could hijack user sessions, steal credentials, or deface the site through client‑side code execution.
Affected Systems
Affected are installations of olivier‑ls PHP‑FTS up to and including version 1.1.2. The vulnerability resides in the src/SearchEngine.php file within the Search Engine component. Any instance of the product that has not been updated to 1.1.3 or later is potentially exposed. System administrators should verify the version currently in use and plan an upgrade if they are running a vulnerable release.
Risk and Exploitability
The CVSS score is 5.1, indicating a moderate severity, and EPSS data is not available. Based on the description, it is inferred that the exploit can be triggered remotely by sending a crafted query to the search endpoint. Because the attack payload is injected into stored content that will be rendered for all users, the risk is significant for sites that expose the search feature to the public or untrusted input.
OpenCVE Enrichment