Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-79jr-8fhm-8wv3: OpenNMS Horizon and Meridian vulnerable to Cross-site Scripting

Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information.

ghsa
#xss#git#auth

OpenNMS Horizon and Meridian vulnerable to Cross-site Scripting

Moderate severity GitHub Reviewed Published Feb 22, 2023 to the GitHub Advisory Database • Updated Feb 22, 2023

Related news

CVE-2023-0846: NMS-14877: Fixed XSS in display of alarm reduction-key by christianpape · Pull Request #5506 · OpenNMS/opennms

Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information.