CVE-2016-6555

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
24/09/2021
Last modified:
01/10/2021

Description

OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in version 18.0.2, released on September 20, 2016.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opennms:opennms:*:*:*:*:*:*:*:* 18.0.2-1 (excluding)