CVE-2025-53122
Severity CVSS v4.0:
MEDIUM
Type:
CWE-89
SQL Injection
Publication date:
26/06/2025
Last modified:
30/06/2025
Description
Improper Neutralization of Special Elements used in an SQL Command (&#39;SQL Injection&#39;) vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection. <br />
<br />
Users<br />
should upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian and<br />
Horizon installation instructions state that they are intended for installation<br />
within an organization&#39;s private networks and should not be directly accessible<br />
from the Internet.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM