PT-2022-22461 · Openteknik Llc · Openteknik Llc Ossn Open Source Social Network

CVE-2022-34966

·

Published

2022-07-25

·

Updated

2023-08-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS
Description The issue is related to an HTML injection vulnerability. This vulnerability can be exploited via the location parameter at the API endpoint "http://ip address/:port/ossn/home".
Recommendations For OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS, consider restricting access to the vulnerable API endpoint "http://ip address/:port/ossn/home" to minimize the risk of exploitation. Avoid using the location parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34966

Affected Products

Openteknik Llc Ossn Open Source Social Network