rymcu forest
cpe:2.3:a:rymcu:forest:*:*:*:*:*:*:*
- <= 0.0.5
A stored cross-site scripting vulnerability has been identified in Rymcu Forest versions through 0.0.5. The issue arises in the User Profile Handler, specifically within the updateUserInfo function of the UserInfoController.java file. This vulnerability allows authenticated users to inject malicious scripts that are executed when other users view the profile.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the profile.
To reproduce this vulnerability, log in with an authenticated user account. Navigate to the user profile update section and inject a script payload into the signature fields. Due to the application's improper input handling, the injected script will be executed when the profile is viewed by other users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.