Back

MEDIUM

Stealing Cookies using Reflected XSS via graph results

Published Feb 23, 2023

Description

Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Affected products

Remediation

Vendor solution

Upgrade to the latest version of Meridian or Horizon.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner OpenNMS
Published Feb 23, 2023
Updated Aug 2, 2024
Reserved Feb 16, 2023

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner OpenNMS
Published Feb 23, 2023
Updated Aug 2, 2024