Overview
The same network overview contained a second XSS vector through the charge parameter. Client-side processing could turn this data into executable content.
Technical findings
This finding also affects /overview/network/, this time through the charge parameter. Its value reached a DOM rendering path without being neutralized for the destination context.
The result was a link whose payload was evaluated by the browser when opened. The core flaw is simple: a URL parameter could cross the boundary between data and executable content.
Versions through 8.12.0 are affected. The fix was released in OpenAtlas 8.13.0.
Why it matters
An attack requires a crafted link and someone to open it. Once executed, the payload runs in the OpenAtlas origin and therefore shares the application’s browser context.
Potential impact
- DOM-based XSS caused by an unfiltered parameter.
Remediation
- Upgrade to OpenAtlas 8.13.0 or later.
- Strictly limit the charge parameter to expected values and data types.
- Avoid unsafe DOM sinks; use safe APIs such as textContent for untrusted data.
- Use CSP as an additional safeguard, not as a replacement for safe handling of output.