VYPR
Medium severity6.1NVD Advisory· Published Feb 20, 2022· Updated Jun 17, 2026

CVE-2022-23054

CVE-2022-23054

Description

Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nasa/openmct2 versions
    cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*range: >=1.3.0,<=1.7.7
    • (no CPE)range: 1.3.0 - 1.7.7
  • nasa/openmctv5
    Range: 1.7.7

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.