Record summary

CVE-2023-40311 has a selected CVSS score of 6.7 (medium).

Description

Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that allow an attacker to store on database and then load on JSPs or Angular templates. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Jordi Miralles Comins for reporting this issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List31.0.8 to < 32.0.2affected
Before 31.0.8unknown

Default status: unaffected

CVE List2020.0.0 to ≤ 2020.1.37affected
2021.0.0 to ≤ 2021.1.29affected
2022.0.0 to ≤ 2022.1.18affected
2023.0.0 to ≤ 2023.1.5affected
GitHub Advisory31.0.8 to < 32.0.2 · Fixed in 32.0.2affected

References

6