Description
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
Remediation
References
https://www.linkedin.com/pulse/xss-nasas-open-mct-v302-visionspace-technologies-ubg4f
Related Vulnerabilities
CVE-2022-31160 Vulnerability in npm package jquery-ui
CVE-2013-6372 Vulnerability in maven package org.jenkins-ci.plugins:subversion
CVE-2020-7709 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2023-39345 Vulnerability in npm package @strapi/strapi
CVE-2017-1000043 Vulnerability in maven package org.webjars.npm:mapbox.js