AI Score
Confidence
High
EPSS
Percentile
17.1%
SSVC
Exploitation
none
Automatable
no
Technical Impact
partial
Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSSΒ via including scripts in one of GET header parameters.Β
Only a part of observed services is vulnerable, but since vendor has not investigated the root problem, it is hard to determine when the issue appears.
[
{
"vendor": "Concept Intermedia",
"product": "S@M CMS",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "3.3"
}
],
"defaultStatus": "unknown"
}
]