CVE-2018-14664

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:theforeman:foreman:1.18.0:*:*:*:*:*:*:*

Information

Published : 2018-10-12 15:15

Updated : 2019-05-14 10:29


NVD link : CVE-2018-14664

Mitre link : CVE-2018-14664


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

theforeman

  • foreman