Impact
Omega Solution HRM OS allows opening an SVG file through the /media/view route. An attacker can create a crafted SVG containing JavaScript that executes in the context of the viewer. This flaw, identified as a typical cross‑site scripting flaw (CWE‑79) coupled with script code injection (CWE‑94), enables arbitrary client‑side code to run during normal file viewing. The attack surface is remote; the exploit is publicly available, meaning that any user who can upload or trigger a view of a malicious SVG can be impacted.
Affected Systems
The affected product is Omega Solution HRM OS, specifically releases up to and including 20260717. No later versions were listed in the vulnerability report. The flaw resides in an undocumented function of the /media/view component that processes SVG file uploads. There are no specific sub‑components beyond the web interface noted.
Risk and Exploitability
The CVSS score of 4.8 places the issue in the medium severity range, and the EPSS score is unavailable, indicating limited data on current exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered remotely through a file upload, the risk of exploitation remains significant until a patch or enforceable mitigation is applied. Attackers would need access to the upload interface or a way to force the server to render the SVG, then rely on victim browsers to execute the embedded script. No vendor patch has been issued; therefore, active mitigation steps are required.
OpenCVE Enrichment