Reflected Cross-Site Scripting Vulnerability in TS3 Manager for Teamspeak3 Servers
CVE-2025-61583

4.3MEDIUM

Key Information:

Vendor

Joni1802

Vendor
CVE Published:
1 October 2025

What is CVE-2025-61583?

A reflected cross-site scripting vulnerability has been found in TS3 Manager, a web interface designed for maintaining Teamspeak3 servers. This issue affects versions 2.2.1 and prior, specifically tied to the error handling mechanism on the login page. Attackers can exploit this vulnerability by embedding malicious scripts in server hostnames, which are executed in the browser context of unsuspecting users without appropriate sanitization. Users are urged to upgrade to version 2.2.2, where this vulnerability has been addressed. For detailed information, refer to the advisory and commits related to this issue.

Affected Version(s)

ts3-manager < 2.2.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61583 : Reflected Cross-Site Scripting Vulnerability in TS3 Manager for Teamspeak3 Servers