/plushcap/analysis/sonar/opennms-vulnerabilities-securing-code-against-attackers-unexpected-ways

OpenNMS Vulnerabilities: Securing Code against Attackers’ Unexpected Ways

What's this blog post about?

An XSS vulnerability was found in OpenNMS, a popular enterprise-grade monitoring solution. The issue is tracked as CVE-2023-0846 and allows an unauthenticated attacker to inject a JavaScript payload into the admin dashboard by exploiting another vulnerability in the application. This can lead to arbitrary code execution on the OpenNMS server once an admin views the dashboard. The vulnerabilities were fixed in OpenNMS 31.0.4.

Company
Sonar

Date published
Feb. 29, 2024

Author(s)
Stefan Schiller

Word count
1945

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.