Back

MEDIUM

Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Published Aug 29, 2025

Description

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user and steal their session cookie details, via  the "/insert/acquisition" petition, "name" parameter.

Affected products

Remediation

Vendor solution

The vulnerabilities have been fixed by the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH) team in version 8.10.1, available at https://github.com/craws/OpenAtlas .

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Aug 29, 2025
Updated Aug 29, 2025
Reserved Apr 16, 2025

CISA Vulnrichment

Updated Aug 29, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Aug 29, 2025
Updated Aug 29, 2025

GitHub

No data