CVE-2023-25827 is a reflected Cross-Site Scripting (XSS) vulnerability affecting OpenTSDB, stemming from insufficient validation of parameters in error messages within its legacy HTTP query API and logging endpoint. This allows an attacker to inject and execute malicious JavaScript in a targeted user's browser. With a CVSS score of 6.1 (Medium), it requires user interaction (UI:R) and has a low impact on confidentiality and integrity (C:L, I:L), but can be exploited over the network (AV:N). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, <= 2.4.1CPE matchmatch criteria | cpe:2.3:a:opentsdb:opentsdb:*:*:*:*:*:*:*:* | ||
>= 0, <= 2.4.1CPE match | cpe:2.3:a:opentsdb:opentsdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.