Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2020-15256 Vulnerability in npm package object-path-set
CVE-2021-26539 Vulnerability in npm package sanitize-html
CVE-2023-40827 Vulnerability in maven package org.pf4j:pf4j
CVE-2020-17516 Vulnerability in maven package org.apache.cassandra:cassandra-all