Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25932

Опубликовано: 01 июн. 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function validateFormInput() performs improper validation checks on the input sent to the userID parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*
Версия от 2015.1.0-1 (включая) до 2019.1.18-1 (включая)
cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*
Версия от 2020.1.0-1 (включая) до 2020.1.6-1 (включая)
cpe:2.3:a:opennms:opennms:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 27.1.0-1 (включая)

EPSS

Процентиль: 50%
0.00264
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
debian
больше 4 лет назад

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0 ...

github
больше 3 лет назад

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.

EPSS

Процентиль: 50%
0.00264
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79