OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Description
Published to the GitHub Advisory Database
Oct 2, 2024
Reviewed
Oct 2, 2024
Published by the National Vulnerability Database
Oct 2, 2024
Last updated
Oct 31, 2024
Summary
The login functionality contains a reflected cross-site scripting (XSS) vulnerability.
Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition
Impact
This issue may lead up to Remote Code Execution (RCE).
References