Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme.
To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Exploitability
AV:NAC:LAT:NPR:LUI:AVulnerable System
VC:NVI:NVA:NSubsequent System
SC:HSI:HSA:N6.2/CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:NInjection