CVE-2026-96258 | onSite internet GmbH Auktion NG Auktionssoftware up to 20260722 Public Password Reset Endpoint /forgotpasswd.html email cross site scripting

SecurityVulns

A vulnerability was found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. It has been classified as problematic. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argument email leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-96258. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More