Impact
An attacker who can create or edit the notification template in the OCS Inventory NG Ocsreports component can embed malicious HTML and JavaScript. The application stores this input without sanitisation, and it is later rendered unescaped when any administrator opens the template customisation view. Because the malicious script runs in the browser with the site's privileges, it can hijack the session or otherwise tamper with that administrator’s interactions. This vulnerability primarily affects confidentiality and integrity for administrators, and enables privilege abuse within the application.
Affected Systems
The flaw exists in the OCS Inventory NG product, specifically the Ocsreports component. All installations that have not applied the corrective release 2.12.6 are affected. An administrator user role is required to create or modify the notification template. No older or newer versions are listed as affected by this vulnerability.
Risk and Exploitability
The flaw carries a CVSS score of 9.2, indicating critical severity. Because an attacker must have administrative access, the attack vector is a web‑based interface dealing with notification templates. No EPSS score is available, so exploitation probability cannot be measured. The vulnerability is not included in CISA KEV, but its high score and potential to hijack privileged sessions make it a high‑value target.
OpenCVE Enrichment