Cross-Site Scripting Flaw in Opencast Media Player
CVE-2025-61788
What is CVE-2025-61788?
The Opencast Media Player is susceptible to a Cross-Site Scripting vulnerability due to insufficient input sanitization of user-provided metadata, such as titles and descriptions. This flaw enables attackers with write access to inject malicious HTML and JavaScript code, which can be executed in the browsers of users accessing the media. Consequently, this opens a potential avenue for unauthorized site modifications or actions performed on behalf of logged-in users. It is important to note that only authenticated users with the capability to upload media and alter metadata can exploit this issue. Users are urged to update to versions 17.8 or 18.2 to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opencast < 17.8 < 17.8
opencast >= 18.0, < 18.2 < 18.0, 18.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
