CVE-2025-61583
Unauthenticated reflected cross-site scripting in `Server` parameter in Ts3 manager <=v2.2.1 .
A reflected cross-site scripting (XSS) vulnerability was identified in TS3 Manager versions 2.2.1 and earlier due to improper handling of user-supplied input in the login error mechanism. Malicious JavaScript embedded in the Server hostname field is reflected back to the client without sanitization and rendered directly in the browser, allowing script execution in the victim’s context.
Identifier
CVE-2025-61583
Affected product
TS3 manager
Disclosed
Oct 1, 2025
Credit
Krishna Agarwal, Swapnil Ade
Proof of Concept
Authentication: Unauthenticated
- In the
Serverfield, input a cross-site scripting payload and fill other fields such as username and password. - click on connect
- Observe payload gets executed
Remediation
Running this software?
If TS3 manager is in your environment, the reproduction steps above are enough to verify exposure yourself. If you would rather have the same class of bug hunted across your own stack, that is what we do as an engagement.