Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-22675

Опубликовано: 06 апр. 2026
Источник: debian
EPSS Низкий

Описание

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitization and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ocsinventory-serverunfixedpackage
ocsinventory-serverno-dsabookwormpackage
ocsinventory-serverignoredbullseyepackage

Примечания

  • https://github.com/OCSInventory-NG/OCSInventory-Server/pull/483

  • Fixed by: https://github.com/OCSInventory-NG/OCSInventory-Server/commit/f81e28a503ded042f037a7837e78f76528754ee7

EPSS

Процентиль: 12%
0.00218
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitization and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

CVSS3: 5.4
nvd
4 месяца назад

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitization and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

CVSS3: 5.4
github
4 месяца назад

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

EPSS

Процентиль: 12%
0.00218
Низкий