Home

Description

OrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating users with script payloads in the name parameter. Attackers can send POST requests to the document endpoint with JavaScript code in the name field to execute arbitrary scripts when users view the application.

PUBLISHED Reserved 2026-02-20 | Published 2026-02-20 | Updated 2026-02-23 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
MEDIUM: 6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

3.0.17
affected

Credits

Ozer Goker finder

References

www.exploit-db.com/exploits/46517 (ExploitDB-46517) exploit

orientdb.dev/ (OrientDB Official Website) product

www.vulncheck.com/...-cross-site-scripting-via-user-creation (VulnCheck Advisory: OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation) third-party-advisory

cve.org (CVE-2019-25448)

nvd.nist.gov (CVE-2019-25448)

Download JSON