PT-2022-22461 · Openteknik Llc · Openteknik Llc Ossn Open Source Social Network

Published

2022-07-25

·

Updated

2023-08-08

·

CVE-2022-34966

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS
Description The issue is related to an HTML injection vulnerability. This vulnerability can be exploited via the location parameter at the API endpoint "http://ip address/:port/ossn/home".
Recommendations For OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS, consider restricting access to the vulnerable API endpoint "http://ip address/:port/ossn/home" to minimize the risk of exploitation. Avoid using the location parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-34966

Affected Products

Openteknik Llc Ossn Open Source Social Network