Threats Tagged 'cve-2025-60916'
View all threats tagged with 'cve-2025-60916'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-60916'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-60916 is a reflected cross-site scripting (XSS) vulnerability found in the /overview/network/ endpoint of the Austrian Archaeological Institute's Openatlas software prior to version 8.12.0. The flaw allows attackers to inject malicious scripts via the 'charge' parameter, which are then executed in the context of a user's browser without requiring user interaction. This vulnerability has a medium severity rating with a CVSS score of 5.4, indicating limited impact on confidentiality and integrity but no impact on availability. Exploitation requires network access and low privileges but no user interaction. While no known exploits are currently reported in the wild, the vulnerability poses a risk of session hijacking, data theft, or unauthorized actions within the affected web application. European organizations using Openatlas, especially research institutions and cultural heritage entities, should prioritize patching and input validation to mitigate this threat. Countries with significant archaeological research infrastructure and Openatlas deployments, such as Austria, Germany, and Italy, are most likely to be affected. Join the discussion | CVE Database V5 | 11/24/2025, 00:00:00 UTC Added: 11/24/2025, 15:41:44 UTC |
Showing 1 to 1 of 1 result