Cross-Site Scripting Flaw in Opencast Media Player
CVE-2025-61788

5.1MEDIUM

Key Information:

Vendor

Opencast

Status
Vendor
CVE Published:
8 October 2025

What is CVE-2025-61788?

The Opencast Media Player is susceptible to a Cross-Site Scripting vulnerability due to insufficient input sanitization of user-provided metadata, such as titles and descriptions. This flaw enables attackers with write access to inject malicious HTML and JavaScript code, which can be executed in the browsers of users accessing the media. Consequently, this opens a potential avenue for unauthorized site modifications or actions performed on behalf of logged-in users. It is important to note that only authenticated users with the capability to upload media and alter metadata can exploit this issue. Users are urged to update to versions 17.8 or 18.2 to mitigate this risk.

Affected Version(s)

opencast < 17.8 < 17.8

opencast >= 18.0, < 18.2 < 18.0, 18.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61788 : Cross-Site Scripting Flaw in Opencast Media Player