CVE-2023-45884

MEDIUM

NASA Open MCT <= 3.1.0 - Cross-Site Request Forgery via flexibleLayout Plugin

Title source: llm
STIX 2.1

Description

Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 21.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
nasa/openmct < 3.1.0
npm/openmct 0 - 3.1.1npm
Published Nov 09, 2023
Tracked Since Feb 18, 2026