Cross-Site Scripting Flaw in Opencast Media Player
CVE-2025-61788
5.1MEDIUM
What is CVE-2025-61788?
The Opencast Media Player is susceptible to a Cross-Site Scripting vulnerability due to insufficient input sanitization of user-provided metadata, such as titles and descriptions. This flaw enables attackers with write access to inject malicious HTML and JavaScript code, which can be executed in the browsers of users accessing the media. Consequently, this opens a potential avenue for unauthorized site modifications or actions performed on behalf of logged-in users. It is important to note that only authenticated users with the capability to upload media and alter metadata can exploit this issue. Users are urged to update to versions 17.8 or 18.2 to mitigate this risk.
Affected Version(s)
opencast < 17.8 < 17.8
opencast >= 18.0, < 18.2 < 18.0, 18.2