CVE-2023-0846

MEDIUM6.1EPSS 0.29%

OpenNMS Horizon and Meridian vulnerable to Cross-site Scripting

Published: 2/22/2023Modified: 11/8/2023

Description

Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (5)