Cross-Site Scripting Vulnerability in OpenAtlas by ACDH-CH
CVE-2025-40709

5.1MEDIUM

Key Information:

Vendor

Acdh-ch

Status
Vendor
CVE Published:
29 August 2025

What is CVE-2025-40709?

The OpenAtlas version 8.9.0 has a Cross-Site Scripting (XSS) vulnerability that arises from insufficient validation of user inputs during specific POST requests. Attackers can leverage this flaw by sending specially designed queries to authenticated users, specifically targeting the '/insert/person/' endpoint. The manipulation of 'name' and 'alias-0' parameters could result in the exposure of session cookie details, presenting a significant security risk for users.

Affected Version(s)

OpenAtlas 8.9.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrea Intilangelo (acme)
.
CVE-2025-40709 : Cross-Site Scripting Vulnerability in OpenAtlas by ACDH-CH