Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4w27-xxvw-958c

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

EPSS

Процентиль: 66%
0.0051
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
больше 8 лет назад

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

CVSS3: 6.1
nvd
больше 7 лет назад

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

CVSS3: 6.1
debian
больше 7 лет назад

foreman before version 1.16.0 is vulnerable to a stored XSS in organiz ...

EPSS

Процентиль: 66%
0.0051
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79