Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at `/opennms/admin/userGroupView/users/updateUser`. This flaw allows assigning `ROLE_ADMIN` security role to a normal user. Using this flaw, an attacker can trick the admin user to assign administrator privileges to a normal user by enticing him to click upon an attacker-controlled website.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Opennms Group OpenNMS 跨站请求伪造漏洞
Vulnerability Description
Opennms Group OpenNMS是美国OpenNMS Group(Opennms Group)公司的一套开源的企业级网络监视和网络管理平台。 OpenNMS Meridian 存在跨站请求伪造漏洞,攻击者可利用该漏洞可以通过引诱普通用户点击攻击者的网站来欺骗管理员用户给普通用户分配管理员特权。
CVSS Information
N/A
Vulnerability Type
N/A