Impact
The vulnerability allows a remote attacker to inject malicious script via the Username parameter in the Add User handler of huanzi‑qch base‑admin. The stored or reflected script executes in the context of the admin interface, giving an attacker the potential to hijack sessions, steal credentials, deface the application, or execute other malicious actions as an authenticated admin. The weakness is reflected in the Common Weakness Enumerations CWE‑79 and CWE‑94, which describe improper handling of user input that could lead to code injection.
Affected Systems
Affected versions include all releases of huanzi‑qch base‑admin up to commit 52816b760cd53244989fd664bbb2b3d4edbfdbf1, with no newer releases identified. Continuous delivery and rolling releases are employed, and an updated version that fixes the flaw is not presently available from the vendor.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate‑severity flaw; the EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector is remote, the exploit is publicly available, and the vendor has not responded to remediation requests, leaving the risk for environments running the affected code at a relatively high level until mitigated.
OpenCVE Enrichment