Opsview Monitor is a virtual appliance designed to be deployed inside the organization’s network infrastructure. It comes bundled with a Web Management Console to monitor and manage hosts and their services. Vulnerabilities described in 7.1 and 7.2 could be abused to execute malicious JavaScript code in the context of a legitimate user. The ‘diagnosticsb2ksy’ parameter of the /rest’ endpoint is vulnerable to Cross-Site Scripting. Other products and versions might be affected, but they were not tested.”]
Source: https://www.coresecurity.com/core-labs/advisories/opsview-monitor-multiple-vulnerabilities

