Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The popup manager fetches HTML from a dynamically constructed component path, injects it into the DOM with .html(), and then explicitly executes embedded scripts via eval(). If an attacker can influence the url parameter, component contents, or upstream component storage, this becomes arbitrary script execution in the application's origin, enabling XSS, session theft, DOM compromise, or privileged action execution.
