Beveiligingsadvies

CVE-2016-2058

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-04-13 16:00:00
Laatst bijgewerkt 2024-08-05 23:17:50
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.