Loading
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.
Use CWE-79, Opentsdb vendor hub and Opentsdb product page to widen CVE-2023-25827 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-36812, CVE-2023-25826 and CVE-2020-35476 for nearby disclosures in the same product family.