First published: Wed Nov 01 2017(Updated: )
A cross-site scripting vulnerability was found in foreman in pages where facts are submitted through insertion of HTML in its name or value. Upstream bug: <a href="http://projects.theforeman.org/issues/21519">http://projects.theforeman.org/issues/21519</a>
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1508551 is classified as medium due to its potential for cross-site scripting attacks.
To fix REDHAT-BUG-1508551, it is recommended to upgrade to the latest version of Foreman where the vulnerability is patched.
The impact of REDHAT-BUG-1508551 allows an attacker to execute arbitrary HTML and JavaScript in the context of a user's browser.
REDHAT-BUG-1508551 affects various versions of The Foreman prior to the vulnerabilities being addressed in the latest updates.
A workaround for REDHAT-BUG-1508551 involves sanitizing user inputs to prevent HTML and JavaScript code injection.