CVE-2017-15125: XSS
A cross-site script vulnerability was found in CloudForms 5.9.0.10 self-service UI snapshot feature.
Other sources
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of this XSS however not all browsers support CSP.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15125?
CVE-2017-15125 is a vulnerability found in CloudForms before 5.9.0.22 that allows for stored XSS attacks on application administrators.
How does CVE-2017-15125 affect CloudForms?
CVE-2017-15125 affects CloudForms before 5.9.0.22 in the self-service UI snapshot feature.
What is the severity of CVE-2017-15125?
The severity of CVE-2017-15125 is medium, with a CVSS score of 5.4.
How can an attacker exploit CVE-2017-15125?
An attacker can exploit CVE-2017-15125 by injecting malicious HTML and JavaScript code into the name field of CloudForms self-service UI snapshot feature.
What is the recommended fix for CVE-2017-15125?
To fix CVE-2017-15125, users should update CloudForms to version 5.9.0.22 or later.