CVE-2018-10854: XSS
A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting in CloudForms 5.9.3.1 build due to improper sanitization of user input in Name field.
Other sources
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10854?
CVE-2018-10854 is a vulnerability in cloudforms version 5.8 and 5.9 that allows for cross-site scripting attacks.
How does CVE-2018-10854 affect cloudforms?
CVE-2018-10854 affects cloudforms version 5.8 and 5.9 by enabling stored cross-site scripting due to improper sanitization of user input in the Name field.
What is the severity of CVE-2018-10854?
The severity of CVE-2018-10854 is medium with a CVSS score of 6.5.
How can I fix CVE-2018-10854?
To fix CVE-2018-10854, upgrade to a version of cloudforms that is not affected by the vulnerability.
Where can I find more information about CVE-2018-10854?
You can find more information about CVE-2018-10854 on the Red Hat errata page and CVE details page.