PT-2022-27658 · Opencaching Deutschland · Oc-Server3

CVE-2022-4586

·

Published

2022-12-17

·

Updated

2022-12-22

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opencaching Deutschland oc-server3 (affected versions not specified)
Description A problematic vulnerability was found in the Cachelist Handler component, specifically in the file htdocs/templates2/ocstyle/cachelists.tpl. The manipulation of the name filter and by filter arguments leads to cross-site scripting. The attack can be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name a9f79c7da78cd24a7ef1d298e6bc86006972ea73. As a temporary workaround, consider restricting access to the cachelists.tpl file or disabling the Cachelist Handler component until a patch is applied. Avoid using the name filter and by filter arguments in the affected component until the issue is resolved.

Exploit

Fix

Improper Neutralization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4586

Affected Products

Oc-Server3