What the vulnerability does
01Description
Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.
Explanation of Vulnerability in Simple Terms
EventPrime versions up to 3.3.9 contain a vulnerability that allows authenticated administrators with high privileges to perform actions affecting confidentiality, integrity, and availability when a user interacts with a malicious link or page. The vulnerability has limited scope but requires both admin-level access and user interaction to exploit.
What an attacker can do
An authenticated admin can leak sensitive data, modify site content, or degrade performance when a user clicks a malicious link.
Potential impact on your site
If an admin account is compromised or an admin is socially engineered, site data and functionality could be affected.
Conditions required to exploit
Attacker must have admin-level access to EventPrime and trick a user into clicking a link or visiting a page.
Key dates
External resources