CVE-2019-10177
published 2019-06-27CVE-2019-10177: A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly…
PriorityP427medium6.5CVSS 3.1
AVNACLPRLUIRSCCLILAL
EPSS
0.96%
57.4th percentile
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | cloudforms | — | — |
| redhat | cloudforms_management_engine | — | — |
| redhat | cloudforms_management_engine | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gcg5-r76p-h8xr: A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5
ghsa_unreviewed·2022-05-24
CVE-2019-10177 [MEDIUM] CWE-79 GHSA-gcg5-r76p-h8xr: A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.
Red Hat
CloudForms: Store XSS in PDF exports feature allows code execution of Javascript and HTML input
vendor_redhat·2019-06-27·CVSS 6.5
CVE-2019-10177 [MEDIUM] CWE-79 CloudForms: Store XSS in PDF exports feature allows code execution of Javascript and HTML input
CloudForms: Store XSS in PDF exports feature allows code execution of Javascript and HTML input
A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which could lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.
It was found that PDF export component in CloudForms was vulnerable to cross-side scripting (XSS) as user input was not properly sanitized. An authenticated attacker with privileges to edit compute could use the XSS vulnerability against users, which could lead to arbitrary code execution, and extraction of the anti-
No detection rules found.
No public exploits indexed.
2019-06-27
Published