Cross-Site Scripting Vulnerability in OpenAtlas from ACDH-CH
CVE-2025-40702
5.1MEDIUM
What is CVE-2025-40702?
A Cross-Site Scripting (XSS) vulnerability exists in OpenAtlas v8.9.0, allowing attackers to exploit inadequate input validation during POST requests. By crafting malicious queries targeting authenticated users, attackers can potentially intercept session cookies through the '/insert/file' petition, specifically utilizing the 'creator' and 'license_holder' parameters. This vulnerability poses significant security risks as it can facilitate unauthorized access to user sessions.
Affected Version(s)
OpenAtlas 8.9.0