DSpace Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in DSpace JSPUI version 6.5. This issue arises within the search and discovery filtering functionality, where user input through the 'filter_type_1' parameter is not properly sanitized. As a result, attackers can inject arbitrary JavaScript that is executed in the context of the user's browser.

Impact

Exploitation of this vulnerability allows for the execution of injected JavaScript in the victim's browser. This could lead to session hijacking, phishing attacks, manipulation of the user interface, or other client-side attacks.

Reproduction

To reproduce this vulnerability, send a request to the DSpace JSPUI 6.5 application with a crafted 'filter_type_1' parameter that includes malicious JavaScript. This can be done by using a URL that contains the injected script, which will be reflected and executed when the page is loaded.

Added: Mar 27, 2026, 4:05 PM
Updated: Mar 27, 2026, 4:05 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
7.7
remediation
0.0
relevance
4.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.