Vulnerability Details CVE-2015-4420
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-4420
-
cpe:2.3:a:opsview:opsview:2.10
-
cpe:2.3:a:opsview:opsview:2.12
-
cpe:2.3:a:opsview:opsview:2.14
-
cpe:2.3:a:opsview:opsview:2.7
-
cpe:2.3:a:opsview:opsview:2.8
-
cpe:2.3:a:opsview:opsview:3.0
-
cpe:2.3:a:opsview:opsview:3.1
-
cpe:2.3:a:opsview:opsview:3.10
-
cpe:2.3:a:opsview:opsview:3.12
-
cpe:2.3:a:opsview:opsview:3.14
-
cpe:2.3:a:opsview:opsview:3.2
-
cpe:2.3:a:opsview:opsview:3.4
-
cpe:2.3:a:opsview:opsview:3.6
-
cpe:2.3:a:opsview:opsview:3.8
-
cpe:2.3:a:opsview:opsview:4.0
-
cpe:2.3:a:opsview:opsview:4.1
-
cpe:2.3:a:opsview:opsview:4.2
-
cpe:2.3:a:opsview:opsview:4.3
-
cpe:2.3:a:opsview:opsview:4.4
-
cpe:2.3:a:opsview:opsview:4.4.0
-
cpe:2.3:a:opsview:opsview:4.4.1
-
cpe:2.3:a:opsview:opsview:4.5.0
-
cpe:2.3:a:opsview:opsview:4.6.2