Aller au contenu

Fiche vulnérabilité

CVE-2025-40708 : faille moyenne craws openatlas (CVSS 5.4)

Description

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user and steal their session cookie details, via  the "/insert/event" petition, "name" parameter.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
29 août 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • craws openatlas

Références

Rechercher une autre vulnérabilité dans la base CVE