Overview
In the OpenAtlas network overview, the color parameter could reach rendered output in a way that executed JavaScript. A crafted link was sufficient; the payload did not have to be stored.
Technical findings
The affected endpoint is /overview/network/. The color parameter came from the request and was inserted into the network view without being handled safely for each output context.
This allowed a link to execute JavaScript in the browser when opened. It is reflected XSS: the payload does not need to be stored in the database.
OpenAtlas versions through 8.12.0 are affected. The issue was fixed in 8.13.0.
Why it matters
The risk is greatest when an authenticated user opens a crafted network-view link. The injected code runs in the OpenAtlas origin; its capabilities depend on the user’s role, session and available features.
Potential impact
- JavaScript execution within the application’s browser context.
Remediation
- Upgrade to OpenAtlas 8.13.0 or later.
- Accept values such as colors only from a narrow allowlist and validate them server-side.
- Encode dynamic values for the actual HTML, attribute or JavaScript context in which they appear.
- Add a restrictive Content Security Policy as defense in depth.