CVE-2015-7518Cross-site Scripting in Foreman

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 51.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 17
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-cr73-cpqp-v63j: Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 12022-05-17
CVEList
CVE-2015-7518: Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 12015-12-17

📋Vendor Advisories

1
Red Hat
foreman: Stored XSS vulnerability in smart class parameters/variables2015-11-26

💬Community

1
Bugzilla
CVE-2015-7518 foreman: Stored XSS vulnerability in smart class parameters/variables2015-11-26
CVE-2015-7518 — Cross-site Scripting in Foreman | cvebase