CVE-2017-7535: XSS
Published Jul 26, 2018
·Updated
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
Affected Software
1 affected component
theforeman foreman<1.16.0
Remediation
Patch Available
Event History
Jul 26, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2017-7535?
CVE-2017-7535 is a vulnerability in Foreman before version 1.16.0 that allows for stored XSS in organizations/locations assignment to hosts.
2
How severe is CVE-2017-7535?
CVE-2017-7535 has a severity rating of 6.1 (Medium).
3
How can CVE-2017-7535 be exploited?
Exploiting CVE-2017-7535 requires a user to actively assign hosts to an organization that contains HTML in its name visible to the user prior to taking action.
4
What software is affected by CVE-2017-7535?
Foreman before version 1.16.0 is affected by CVE-2017-7535.
5
Is there a fix for CVE-2017-7535?
Upgrading to Foreman version 1.16.0 or later fixes CVE-2017-7535.