OCS Inventory NG Server version 2.12.3 and prior contain...
Moderate severity
Unreviewed
Published
Apr 7, 2026
to the GitHub Advisory Database
•
Updated Apr 7, 2026
Description
Published by the National Vulnerability Database
Apr 6, 2026
Published to the GitHub Advisory Database
Apr 7, 2026
Last updated
Apr 7, 2026
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.
References