CVE-2019-25323: Heatmiser Netmonitor
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to inject malicious HTML code through the outputtitle parameter. Attackers can craft specially formatted POST requests to the outputtitle parameter to execute arbitrary HTML and potentially manipulate the web interface's displayed content.
Affected products
- Heatmiser Heatmiser Netmonitor: version 3.03 only
Published 2026-02-12. Last modified 2026-06-17.