What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in intelligentDesign Keymaster Chord Notation Free keymaster-chord-notation-free allows Stored XSS.This issue affects Keymaster Chord Notation Free: from n/a through <= 1.0.2.
Explanation of Vulnerability in Simple Terms
02Summary
Keymaster Chord Notation Free versions up to 1.0.2 contain a cross-site scripting vulnerability that allows attackers with low-level site access to inject malicious scripts. When a victim visits an affected page, the attacker's code runs in their browser with access to their session. The vulnerability requires user interaction and can affect other users on the site.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in other users' browsers and steals their session data or performs actions on their behalf.
Potential impact on your site
04Site Impact
Site visitors' sessions and data can be compromised by low-privilege users; attackers can deface content or redirect users to malicious sites.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege account on the site; victim must visit a page containing the injected payload.
Key dates
06Disclosure timeline
November 19, 2024
CVE published
April 28, 2026
Record updated