Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10777

Опубликовано: 03 авг. 2020
Источник: redhat
CVSS3: 6.5

Описание

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

A flaw was found in the Report Menu of Red Hat CloudForms where the title field was not properly sanitized for HTML and JavaScript inputs. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that Content Security Policy can prevent exploitation of this XSS however not all browsers support CSP.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-94->CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1847605CloudForms: Cross Site Scripting in report menu title / HTML Code Injection

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.

CVSS3: 6.5
fstec
больше 5 лет назад

Уязвимость программной платформы для управления виртуальными средами CloudForms Management Engine, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

6.5 Medium

CVSS3