Cross-Site Scripting in OpenAtlas v8.9.0 from Austrian Centre for Digital Humanities
CVE-2025-40703
5.1MEDIUM
What is CVE-2025-40703?
OpenAtlas v8.9.0 contains a Cross-Site Scripting vulnerability that arises from insufficient validation of user inputs. When an attacker sends specially crafted POST requests, they can exploit this flaw through the '/insert/group' endpoint, particularly targeting 'name' and 'alias-0' parameters. This allows unauthorized users to craft queries that can steal session cookie details from authenticated users, posing significant risks to user security.
Affected Version(s)
OpenAtlas 8.9.0