Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Opencast - CVE-2025-61788
Published: April 23, 2026
Opencast
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to improper neutralization of script-related html tags in paella player 7 when rendering user-supplied metadata. A remote user can inject malicious html and javascript into metadata fields to execute arbitrary script in a user's browser.
Exploitation requires write access to the system, such as the ability to upload media and modify metadata.