Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14664

Опубликовано: 10 окт. 2018
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

A cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged users.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1638130foreman: Persisted XSS on all pages that use breadcrumbs

EPSS

Процентиль: 52%
0.00291
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 7 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

CVSS3: 5.4
debian
больше 7 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site sc ...

CVSS3: 5.4
github
больше 3 лет назад

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

EPSS

Процентиль: 52%
0.00291
Низкий

7.6 High

CVSS3