Uploaded image for project: 'Observium'
  1. Observium
  2. OBS-4584

HTML injection vulnerability

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Minor
    • None
    • CE-22.5
    • Discovery

    Description

      Observium is vulnerable to HTML injection via LLDP neighbour discovery. This happens if a port sees a neighbour with a system name of <script>alert('injection!')</script>.

      In the "neighbours view" of that port, a yellow triangle will be shown to indicate that autodiscovery is not working properly. Hovering over that triangle will trigger the injected payload.

       

      Keep up the good work! Cheers!

      Attachments

        Activity

          People

            landy Mike Stupalov
            zluudg zluudg
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: