First published: Fri Sep 24 2021(Updated: )
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Opennms Opennms | <18.0.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2016-6555.
CVE-2016-6555 has a severity level of high.
CVE-2016-6555 affects OpenNMS version 18.0.1 and prior.
CVE-2016-6555 allows an attacker to store a malicious XSS payload that can be triggered when a user views the events list page on the web UI.
To mitigate CVE-2016-6555, upgrade OpenNMS to version 18.0.2-1 or newer.