Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a stored Cross-Site Scripting vulnerability within the notification template feature of a specific reporting tool. The issue arises when administrators input malicious content that is then stored and executed, potentially compromising the sessions of other administrators using the template customization view.
- Stored malicious content can run unauthorized code.
- Threat to administrator sessions and application security.
- Confirm relevance and potential exposure within your environment.
Attack Path
How an attacker could exploit the issue
An attacker with administrator privileges can inject malicious HTML into notification templates. When other administrators view these templates, the stored malicious content executes as JavaScript, potentially compromising their sessions.
- Requires administrator privileges.
- Vulnerable notification templates.
- Compromise of administrator sessions.
Live Threat
Current exploitation, exposure, and threat context
A stored Cross-Site Scripting vulnerability in the notification template functionality could allow an authenticated administrator to inject malicious HTML and JavaScript. When other administrators view the notification template customization, this script could execute within their browser's security context, potentially affecting their active sessions.
- Administrator sessions.
- Via crafted notification templates.
- Unauthorized administrative actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The stored cross-site scripting vulnerability in the notification template functionality is likely to affect application owners and platform teams responsible for the OCS Inventory NG instance. The first actionable step is to identify all deployed instances of the affected technology, confirm their network exposure and business criticality, and then identify the accountable system owner to initiate a risk-based remediation plan.
- Application owners should own the remediation.
- Verify administrative access and template usage.
- Plan remediation based on exposure and criticality.