PT-2016-4990 · Hobbit Monitor Solutions+1 · Xymon+1
Jccleaver
·
Published
2016-02-26
·
Updated
2018-10-09
·
CVE-2016-2058
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Xymon versions 4.1.x through 4.3.x before 4.3.25
Description
The issue allows remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page. Additionally, remote authenticated users can inject arbitrary web script or HTML via an acknowledgement message, which is not properly handled in the "status" page.
Recommendations
For Xymon versions 4.1.x through 4.3.x before 4.3.25, update to version 4.3.25 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Xymon