What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extra ohio-extra allows DOM-Based XSS.This issue affects Ohio Extra: from n/a through <= 3.6.0.
Explanation of Vulnerability in Simple Terms
02Summary
Ohio Extra versions 3.6.0 and earlier contain a cross-site scripting vulnerability that allows attackers with low-level user access to inject malicious scripts. The vulnerability requires user interaction and affects the integrity and confidentiality of site data. Administrators should update to a version newer than 3.6.0.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that execute in other users' browsers when they interact with affected pages.
Potential impact on your site
04Site Impact
Authenticated users with low privileges can compromise other users' sessions, steal data, or deface content.
Conditions required to exploit
05Prerequisites
Attacker needs low-level user account access and must trick a victim into visiting a crafted link or page.
Key dates
06Disclosure timeline
October 31, 2025
CVE published
April 28, 2026
Record updated