PT-2022-22461 · Openteknik Llc · Openteknik Llc Ossn Open Source Social Network
Published
2022-07-25
·
Updated
2023-08-08
·
CVE-2022-34966
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS
Description
The issue is related to an HTML injection vulnerability. This vulnerability can be exploited via the
location parameter at the API endpoint "http://ip address/:port/ossn/home".Recommendations
For OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK version 6.3 LTS, consider restricting access to the vulnerable API endpoint "http://ip address/:port/ossn/home" to minimize the risk of exploitation. Avoid using the
location parameter in this endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openteknik Llc Ossn Open Source Social Network