PT-2025-41298 · Opencast+1 · Opencast+1
Miesgre
·
Published
2025-10-08
·
Updated
2025-10-10
·
CVE-2025-61788
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opencast versions prior to 17.8
Opencast versions prior to 18.2
Description
Opencast is a platform for managing educational audio and video content. Prior to versions 17.8 and 18.2, the paella component included and rendered user inputs, such as title and description metadata, without proper filtering. This allows attackers with write access to inject malicious HTML and JavaScript into the player, which can then be executed in the browsers of users viewing the media. This could potentially be used to modify the site or perform actions on behalf of logged-in users. The attack requires write access to the system, such as the ability to upload media and modify metadata, and cannot be exploited by unauthenticated users.
Recommendations
Update Opencast to version 17.8 or later.
Update Opencast to version 18.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencast
Paella