OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting. https://fluidattacks.com/advisories/creed/ https://ocsinventory-ng.org/
Created ocsinventory-agent tracking bugs for this issue: Affects: epel-all [bug 2256832] Affects: fedora-all [bug 2256833]
Per https://fluidattacks.com/advisories/creed/ the vulnerability only impacts OCSInventory-ocsreports which is not part of ocsinventory-agent. I don't think there is anything required from the ocsinventory-agent side on this.
Okay, that was my unfamiliarity with this package. Sorry for the spam. Please close as not affected.
Honestly, I'm pretty happy this happened as it shows more eyes than just mine are looking out :)