PT-2025-47932 · Austrian Archaeological Institute · Openatlas

Published

2025-11-24

·

Updated

2025-11-24

·

CVE-2025-60916

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Austrian Archaeological Institute Openatlas versions prior to 8.12.0
Description A reflected cross-site scripting (XSS) issue exists in the /overview/network/ API endpoint of Openatlas. This allows attackers to execute arbitrary code within a user's browser by injecting a malicious payload into the charge parameter.
Recommendations Update to version 8.12.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60916

Affected Products

Openatlas