CVE-2013-5695

Opsview < 4.4 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to info/host/ or (3) viewport/, (4) back parameter to login, or (5) "from" parameter to status/service/recheck.

Scores

EPSS 0.0022
EPSS Percentile 45.0%

Details

CWE
CWE-79
Status published
Products (25)
opsview/opsview < 4.4
opsview/opsview < 4.4
opsview/opsview
opsview/opsview
opsview/opsview
opsview/opsview
opsview/opsview
opsview/opsview
opsview/opsview
opsview/opsview
... and 15 more
Published Nov 05, 2013
Tracked Since Feb 18, 2026