TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames are executed in the victim's browser context without proper sanitization. This issue is fixed in version 2.2.2.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joni1802
Joni1802 ts3 Manager |
|
| CPEs | cpe:2.3:a:joni1802:ts3_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Joni1802
Joni1802 ts3 Manager |
Thu, 02 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Teamspeak3 Manager Project
Teamspeak3 Manager Project ts3 Manager |
|
| Vendors & Products |
Teamspeak3 Manager Project
Teamspeak3 Manager Project ts3 Manager |
Wed, 01 Oct 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames are executed in the victim's browser context without proper sanitization. This issue is fixed in version 2.2.2. | |
| Title | TS3 Manager is vulnerable to unauthenticated reflected XSS attack due to insecure error handling | |
| Weaknesses | CWE-20 CWE-80 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-01T22:27:59.716Z
Updated: 2025-10-02T18:01:57.231Z
Reserved: 2025-09-26T16:25:25.150Z
Link: CVE-2025-61583
Updated: 2025-10-02T18:01:51.616Z
Status : Analyzed
Published: 2025-10-01T23:15:30.507
Modified: 2025-10-20T18:07:20.587
Link: CVE-2025-61583
No data.