CVE-2016-2058: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or (2) remote authenticated users to inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2058?
CVE-2016-2058 has a medium severity rating due to its potential to allow remote users to execute arbitrary scripts.
How do I fix CVE-2016-2058?
To fix CVE-2016-2058, upgrade Xymon to version 4.3.25 or later, which addresses the vulnerability.
What are the affected versions of Xymon in CVE-2016-2058?
CVE-2016-2058 affects Xymon versions 4.1.x, 4.2.x, and 4.3.x prior to 4.3.25.
Can users exploit CVE-2016-2058 without authentication?
Yes, CVE-2016-2058 can be exploited by unauthenticated remote Xymon clients through status messages.
Is there a workaround for CVE-2016-2058?
While upgrading to a patched version is recommended, restricting access to the detailed status page can serve as a temporary workaround.