Openmct XSS via the “Condition Widget”
CVE-2022-23053

6.1MEDIUM

Key Information:

Vendor

Nasa

Status
Vendor
CVE Published:
20 February 2022

What is CVE-2022-23053?

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

Affected Version(s)

openmct 1.7.7

openmct 1.3.0 < 1.3.0*

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Elkabes
.
CVE-2022-23053 : Openmct XSS via the “Condition Widget”