← volver
CVE-2023-0846

Unauthenticated, stored XSS in display of alarm reduction-key

CVSS 6.7 MEDIUMEPSS 0.5%CWE-79
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.7EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
22 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →