Karaz Karazal Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in the Karazal application, affecting all versions prior to April 14, 2025. The issue arises in the lang parameter of the default URI, allowing attackers to inject malicious JavaScript that could be executed in the context of the victim's browser.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, append a malicious payload to the lang parameter in the URL. When the crafted link is opened, the injected script will execute, demonstrating the cross-site scripting vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
