Back to search
CVE-2015-7518
Published: Dec 17, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2016:0174
vendor-advisory
x_refsource_REDHAT
[oss-security] 20151209 CVE-2015-7518: Foreman stored XSS in parameter information popup
mailing-list
x_refsource_MLIST
http://projects.theforeman.org/issues/12611
x_refsource_CONFIRM
http://theforeman.org/security.html#2015-7518
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now