Executive brief
Ocsreports is an open-source asset management platform used to track hardware and software across IT infrastructure. This vulnerability allows a malicious administrator to inject JavaScript code into notification templates that will execute in the browsers of other administrators viewing those templates, potentially allowing account hijacking or unauthorized actions within the application.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the notification template functionality at endpoint /ocsreports/?function=notification. An authenticated user with administrator privileges can inject malicious HTML and JavaScript into template fields, which are stored without sanitization. When other administrators access the template customization view, the malicious script executes within their browser in the application's security context. Attack requires admin-level access and user interaction (viewing the template page). Successful exploitation could compromise admin sessions, enabling session hijacking or privilege escalation. The vulnerability was patched in OCS Inventory NG version 2.12.6.
Affected products
- OCS Inventory Ocsreports before 2.12.6
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fixed in version 2.12.6