Back

MEDIUM

Multiple stored and reflected Cross-site Scripting in webapp

Published Feb 23, 2023

Description

Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Affected products

Remediation

Vendor solution

Upgrade to a newer version of Meridian or Horizon.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner OpenNMS
Published Feb 23, 2023
Updated Aug 2, 2024
Reserved Feb 16, 2023

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner OpenNMS
Published Feb 23, 2023
Updated Aug 2, 2024