Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2016:0174 | vendor advisory |
http://www.openwall.com/lists/oss-security/2015/12/09/6 | mailing list |
http://projects.theforeman.org/issues/12611 | |
http://theforeman.org/security.html#2015-7518 | vendor advisory |