PT-2026-97152 · Onsite Internet Gmbh · Auktion Ng

·

CVE-2026-96258

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions onSite internet GmbH Auktion NG Auktionssoftware versions prior to 20260722
Description A remote cross site scripting issue exists within the Public Password Reset Endpoint component. The flaw occurs in the /forgotpasswd.html endpoint when the email argument is manipulated. Cross site scripting is a technique where malicious scripts are injected into trusted websites.
Recommendations Update onSite internet GmbH Auktion NG Auktionssoftware to a version later than 20260722. Avoid using the email argument in the /forgotpasswd.html endpoint until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96258

Affected Products

Auktion Ng