Description
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitization and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.
References (3)
Core 3
Core References
Issue Tracking issue-tracking
https://github.com/OCSInventory-NG/OCSInventory-Server/pull/483
Patch patch
https://github.com/OCSInventory-NG/OCSInventory-Server/commit/78faf2ca8b897141ba4d337d75692ab8e405bd4e
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ocs-inventory-ng-server-stored-xss-via-user-agent
Scores
CVSS v3
5.4
EPSS
0.0022
EPSS Percentile
12.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (3)
OCS Inventory/OCS Inventory NG Server
< 2.12.3
OCS Inventory/OCS Inventory NG Server
78faf2ca8b897141ba4d337d75692ab8e405bd4e
ocsinventory-ng/ocs_inventory_server
< 2.12.3
Published
Apr 06, 2026
Tracked Since
Apr 07, 2026