PT-2025-40307 · Unknown · Ts3-Manager+1

·

CVE-2025-61583

·

Published

2025-10-01

·

Updated

2025-10-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TS3 Manager versions prior to 2.2.2
Description TS3 Manager, a web interface for Teamspeak3 servers, contains a reflected cross-site scripting issue. The problem resides in the login page's error handling, specifically when processing server hostnames. Malicious scripts within these hostnames can be executed in a user's browser due to insufficient sanitization.
Recommendations Update to version 2.2.2 or later.

Exploit

Fix

XSS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61583
GHSA-QW6J-37R6-M93G

Affected Products

Ts3-Manager
Teamspeak3