Impact
A flaw in the LabelFormat field of Bacularis appears when a new pool is added. The application fails to sanitize or escape the string, allowing an attacker to inject a Cross‑Site Scripting payload. If a user interacts with the vulnerable webpage, the malicious script can read or modify the browser’s state, steal authentication cookies, or perform actions on behalf of that user. The effect is limited to the victim’s browser session and does not provide system‑level privileges.
Affected Systems
The issue affects the Bacularis software in versions 1.0.0 through 6.5.1. Any deployment running these releases and utilizing the pool‑creation feature is susceptible.
Risk and Exploitability
The CVSS score is not publicly provided, and the EPSS score is unavailable. The vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires access to the Bacularis web interface and a victim who will load the injected content. The risk is therefore constrained to users interacting with the interface, but the potential for credential theft and session hijacking is significant. If the application is exposed to untrusted clients, the impact could be amplified, especially when users rely on preserved authentication tokens.
OpenCVE Enrichment