PT-2023-20332 · Opentsdb · Opentsdb

·

CVE-2023-25827

·

Published

2023-05-03

·

Updated

2023-05-10

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenTSDB (affected versions not specified)
Description The issue is caused by insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint. This allows an attacker to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. The issue is related to a reflected XSS vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-25827
GHSA-9CHV-3W6C-JQ9W

Affected Products

Opentsdb