CVE-2023-0846

MEDIUM6.1EPSS 0.29%

OpenNMS Horizon and Meridian vulnerable to Cross-site Scripting

Published: 2/22/2023Modified: 11/8/2023
Also known as:GHSA-79jr-8fhm-8wv3

Description

Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (5)