CVE-2018-1000225: XSS
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. This attack appear to be exploitable via "network connectivity". Sending unauthenticated JavaScript payload to the Cobbler XMLRPC API (/cobblerapi).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000225?
CVE-2018-1000225 is considered a moderate severity vulnerability due to its potential for privilege escalation.
Who is affected by CVE-2018-1000225?
CVE-2018-1000225 affects Cobbler versions 2.6.11 and earlier, including potentially older versions.
How can I fix CVE-2018-1000225?
To fix CVE-2018-1000225, upgrade Cobbler to version 2.6.12 or later.
What type of vulnerability is CVE-2018-1000225?
CVE-2018-1000225 is a Cross Site Scripting (XSS) vulnerability in the cobbler-web component.
What can happen if CVE-2018-1000225 is exploited?
Exploitation of CVE-2018-1000225 can result in privilege escalation to an admin account.