Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2021-27884 Vulnerability in npm package yapi-vendor
CVE-2020-28470 Vulnerability in npm package @scullyio/scully
CVE-2022-43484 Vulnerability in maven package org.terasoluna.gfw:terasoluna-gfw-common
CVE-2020-13956 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2019-14653 Vulnerability in maven package org.webjars.npm:editor.md