Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25935

Опубликовано: 25 мая 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function add() performs improper validation checks on the input sent to the foreign-source parameter. Due to this flaw an attacker could bypass the existing regex validation and inject an arbitrary script which will be stored in the database.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:opennms:horizon:*:*:*:*:*:*:*:*
Версия от 17.0.0 (включая) до 27.1.0 (включая)
cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*
Версия от 2015.1.0 (включая) до 2019.1.18 (включая)
cpe:2.3:a:opennms:meridian:*:*:*:*:*:*:*:*
Версия от 2020.1.0 (включая) до 2020.1.7 (включая)

EPSS

Процентиль: 49%
0.00263
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
debian
больше 4 лет назад

In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1 ...

github
больше 3 лет назад

In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `add()` performs improper validation checks on the input sent to the `foreign-source` parameter. Due to this flaw an attacker could bypass the existing regex validation and inject an arbitrary script which will be stored in the database.

EPSS

Процентиль: 49%
0.00263
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79