Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6320

Опубликовано: 10 авг. 2016
Источник: redhat
CVSS3: 6.1
CVSS2: 4.9
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.

A cross-site scripting (XSS) flaw was found in the "Device Identifier" field of the new host provisioning components of Red Hat Satellite. A user able to create a new host could exploit this flaw to perform XSS attacks against other Satellite users.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1365785satellite6: stored XSS while provisioning new host

EPSS

Процентиль: 57%
0.00348
Низкий

6.1 Medium

CVSS3

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.4
nvd
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.

CVSS3: 5.4
debian
больше 9 лет назад

Cross-site scripting (XSS) vulnerability in app/assets/javascripts/hos ...

CVSS3: 5.4
github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.

EPSS

Процентиль: 57%
0.00348
Низкий

6.1 Medium

CVSS3

4.9 Medium

CVSS2