MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 23:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-85453
Mitre link : CVE-2026-85453
CVE.ORG link : CVE-2026-85453
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
