PT-2026-21319 · Orientdb · Orientdb
Ozer Goker
·
Publicado
2026-02-20
·
Atualizado
2026-02-24
·
CVE-2019-25449
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OrientDB version 3.0.17
Description
The software contains a reflected cross-site scripting issue that allows attackers to inject malicious scripts. Attackers can send POST requests to the ''/document/demodb/-1:-1'' API endpoint with script tags in the
name parameter to execute arbitrary JavaScript in users' browsers. The attack involves submitting crafted JSON payloads to the document endpoint.Recommendations
Apply input validation and sanitization to the
name parameter in the ''/document/demodb/-1:-1'' API endpoint to prevent the injection of script tags.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Orientdb