CVE-2026-96258: onSite internet GmbH Auktion NG Auktionssoftware Public Password Reset Endpoint forgotpasswd.html cross site scripting
A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argument email leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The affected endpoint is public, and exploitation can be performed remotely. The provided information does not indicate that authentication or elevated privileges are required, though user interaction is required for the XSS impact.
Which deployments may be affected?
onSite internet GmbH Auktion NG Auktionssoftware versions up to 20260722 are identified as affected. The issue is in the public password-reset endpoint at /forgotpasswd.html, specifically when handling the email argument.
What should teams do if a fix is not immediately available?
Restrict or temporarily disable public access to /forgotpasswd.html where operationally feasible, and ensure the email parameter is safely encoded before being reflected in responses. Monitor requests to this endpoint for suspicious email values containing markup or script-like payloads.
How urgent is mitigation?
The exploit has been publicly disclosed and may be used. Although the reported severity is medium and user interaction is required, the endpoint is remotely reachable and intended for unauthenticated users.