PT-2025-47928 · Austrian Archaeological Institute · Openatlas

Published

2025-11-24

·

Updated

2025-11-28

·

CVE-2025-60914

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Austrian Archaeological Institute Openatlas versions prior to 8.12.0
Description A flaw exists in access control within Austrian Archaeological Institute Openatlas. This allows attackers to gain access to sensitive information by sending a specially crafted GET request to the /display logo endpoint. The request is crafted to bypass security checks.
Recommendations Update to version 8.12.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60914

Affected Products

Openatlas