Impact
TS3 Manager’s /api/download handler returns the value of an attacker-controlled port query parameter in an error message that is sent as plain text/html without a Content Security Policy. Because the token cookie is not marked HttpOnly, Secure, or SameSite, a reflected script can read that cookie, decode the JWT, and obtain the TeamSpeak server’s cleartext ServerQuery password. With an active operator session and user interaction, the attacker can then hijack the operator’s session and execute administrative commands on the managed server. The vulnerability therefore provides the attacker with privileged access to the TeamSpeak server after authentication and a crafted link is visited.
Affected Systems
All installations of TS3 Manager released before version 2.2.6 are affected. The latest official release, v2.2.6, contains a fix that removes the insecure handling of the port parameter and prevents the reflected XSS. No other vendor or product variants are listed as affected.
Risk and Exploitability
The vulnerability is scored as CVSS 8.2, indicating a high severity misconfiguration that leads to serious privilege escalation. The EPSS score of below 1% suggests that exploitation is currently rare, and the issue is not yet catalogued in CISA’s KEV list. Exploitation requires a legitimate operator account, user interaction with a crafted link, and a web browser that accepts the reflected payload. When these conditions are met, an attacker can gain full administrative control over the TeamSpeak server. The lack of a Content Security Policy and insecure cookie practices are the core technical weaknesses that enable this attack.
OpenCVE Enrichment