CVE Database
/

CVE-2017-15100

Back to search

CVE-2017-15100

Published: Nov 27, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.

VendorProductVersions

Foreman Project

Foreman

affected
1.2 and later, a fix is planned for 1.16.0

Weaknesses (CWE)

References

RHSA-2018:2927
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now