CVE-2023-45884
- EPSS 0.09%
- Veröffentlicht 09.11.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:33
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
CVE-2023-45885
- EPSS 0.12%
- Veröffentlicht 09.11.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:27:33
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.
CVE-2023-45282
- EPSS 0.08%
- Veröffentlicht 06.10.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:41
In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.
CVE-2022-22126
- EPSS 0.24%
- Veröffentlicht 20.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:13
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and...
CVE-2022-23053
- EPSS 0.24%
- Veröffentlicht 20.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:53
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 ver...
CVE-2022-23054
- EPSS 0.24%
- Veröffentlicht 20.02.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:47:53
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 versi...