{"id":"CVE-2022-23054","summary":"Openmct XSS via the “Summary Widget”","details":"Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.","modified":"2026-08-12T03:51:43.485397516Z","published":"2022-02-20T19:00:17Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23054.json","cna_assigner":"Mend","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/23xxx/CVE-2022-23054.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23054"},{"type":"FIX","url":"https://github.com/nasa/openmct/commit/abc93d0ec4b104dac1ea5f8a615d06e3ab78934a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nasa/openmct","events":[{"introduced":"bbe3847bffbad0fb537ebd69766c8edfcf6e81ff"},{"fixed":"abc93d0ec4b104dac1ea5f8a615d06e3ab78934a"}],"database_specific":{"cpe":"cpe:2.3:a:nasa:openmct:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.3.0"},{"last_affected":"1.7.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.7.7"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23054.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}