Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate the web interface's displayed content.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Heatmiser
Heatmiser heatmiser Netmonitor |
|
| Vendors & Products |
Heatmiser
Heatmiser heatmiser Netmonitor |
Fri, 13 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate the web interface's displayed content. | |
| Title | Heatmiser Netmonitor 3.03 - HTML Injection | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-12T22:48:35.906Z
Updated: 2026-02-13T17:13:42.949Z
Reserved: 2026-02-12T14:34:24.172Z
Link: CVE-2019-25323
Updated: 2026-02-13T17:13:34.991Z
Status : Awaiting Analysis
Published: 2026-02-12T23:16:04.070
Modified: 2026-02-13T14:23:48.007
Link: CVE-2019-25323
No data.