CVE-2023-0867

MEDIUM6.1EPSS 0.28%

OpenNMS Meridian and Horizon vulnerable to Cross-site Scripting

Published: 2/23/2023Modified: 11/8/2023

Description

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (5)