Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xq8-2vfq-6q92

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

EPSS

Процентиль: 52%
0.00291
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.6
redhat
больше 7 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

CVSS3: 5.4
nvd
больше 7 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

CVSS3: 5.4
debian
больше 7 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site sc ...

EPSS

Процентиль: 52%
0.00291
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79