Beveiligingsadvies

CVE-2016-6555

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-06-15 18:35:43
Laatst bijgewerkt 2024-09-17 01:41:54
Toegewezen door rapid7
CVSS-score 7.1
Status PUBLISHED

Beschrijving

OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.