CVE-2014-3960: XSS
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3960?
CVE-2014-3960 has been classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2014-3960?
To mitigate CVE-2014-3960, upgrade to OpenNMS version 1.12.7 or later, which addresses the vulnerabilities.
What types of vulnerabilities are associated with CVE-2014-3960?
CVE-2014-3960 consists of multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts or HTML.
Which versions of OpenNMS are affected by CVE-2014-3960?
CVE-2014-3960 affects OpenNMS versions prior to 1.12.7 and specific earlier versions including 1.9.0 to 1.12.5.
What can happen if CVE-2014-3960 is exploited?
If exploited, CVE-2014-3960 can allow attackers to execute malicious scripts in the context of a user's session, leading to potential data theft or session hijacking.