PT-2022-27414 · Opencaching Deutschland · Opencaching Deutschland Oc-Server3
Published
2022-12-15
·
Updated
2022-12-20
·
CVE-2022-4514
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opencaching Deutschland oc-server3 (affected versions not specified)
Description
A problematic vulnerability was found in Opencaching Deutschland oc-server3, affecting an unknown function of the file htdocs/lang/de/ocstyle/varset.inc.php. The manipulation of the
varvalue argument leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, it is recommended to apply a patch with the name 4bdd6a0e7b7760cea03b91812cbb80d7b16e3b5f. As a temporary workaround, consider restricting access to the
varset.inc.php file until the patch is applied. Additionally, avoid using the varvalue argument in the affected function until the issue is resolved.Fix
Improper Neutralization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opencaching Deutschland Oc-Server3