Cross-Site Scripting Vulnerability in OpenAtlas by ACDH-CH
CVE-2025-40709
5.1MEDIUM
What is CVE-2025-40709?
The OpenAtlas version 8.9.0 has a Cross-Site Scripting (XSS) vulnerability that arises from insufficient validation of user inputs during specific POST requests. Attackers can leverage this flaw by sending specially designed queries to authenticated users, specifically targeting the '/insert/person/' endpoint. The manipulation of 'name' and 'alias-0' parameters could result in the exposure of session cookie details, presenting a significant security risk for users.
Affected Version(s)
OpenAtlas 8.9.0