An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWptdjQtNzN2Mi1wdmdj

Moderate EPSS: 0.00488% (0.64624 Percentile) EPSS:

Cross-site Scripting in OpenNMS Horizon

Affected Packages Affected Versions Fixed Versions
maven:org.opennms:opennms >= 1.0.0, < 27.1.1 27.1.1
0 Dependent packages
0 Dependent repositories

Affected Version Ranges

All affected versions

All unaffected versions

31.0.3

In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting since there is no validation on the input being sent to the name parameter in noticeWizard endpoint. Due to this flaw an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files.

References: