LOW
onSite internet GmbH
CVE published 2026-09-23
CVE-2026-96258
A vulnerability was found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722, affecting the Public Password Reset Endpoint. The manipulation of the email argument leads to cross-site scripting. This issue can be exploited remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted but did not respond.