Executive brief
TAO 2.0 is a suite used for profile and personal data management. An authenticated user can inject malicious code into their profile information, which is then stored and executed when other users (including administrators) view that profile. This could allow attackers to steal session data, impersonate users, or perform unauthorized actions.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the profile management functionality of T-Systems TAO 2.0 suite due to insufficient input sanitization and output encoding in profile fields. Authenticated users can inject arbitrary HTML and JavaScript into personal data fields, which is stored without validation and executed in the browsers of other users who view the affected profile. Attack requires user authentication and victim interaction (viewing a malicious profile), but the attacker can target administrative staff to achieve privilege escalation. Successful exploitation allows arbitrary JavaScript execution, session hijacking, credential theft, and unauthorized actions performed with the victim's permissions.
Affected products
- T-Systems TAO 2.0
Timeline
- 2026-09-18: disclosed