An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
2017-11-27T14:29:00.397
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | theforeman | foreman | < 1.16.0 | Yes |
Application | redhat | satellite | 6.4 | Yes |
Application | redhat | satellite_capsule | 6.4 | Yes |