Home

Description

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames are executed in the victim's browser context without proper sanitization. This issue is fixed in version 2.2.2.

PUBLISHED Reserved 2025-09-26 | Published 2025-10-01 | Updated 2025-10-02 | Assigner GitHub_M




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Problem types

CWE-20: Improper Input Validation

CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Product status

< 2.2.2
affected

References

github.com/...anager/security/advisories/GHSA-qw6j-37r6-m93g

github.com/...ommit/3a069915f97a6f5dae1fe0b2e32aa11a69d83b5e

cve.org (CVE-2025-61583)

nvd.nist.gov (CVE-2025-61583)

Download JSON