PT-2025-47933 · Austrian Archaeological Institute · Openatlas

Published

2025-11-24

·

Updated

2025-11-24

·

CVE-2025-60917

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Austrian Archaeological Institute Openatlas versions prior to 8.12.0
Description A reflected cross-site scripting (XSS) issue exists in the /overview/network/ API endpoint of Openatlas. This allows attackers to execute arbitrary code within a user's browser by injecting a malicious payload into the color parameter.
Recommendations Update to version 8.12.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60917

Affected Products

Openatlas