foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://projects.theforeman.org/issues/20963 | vendor advisory |
http://www.securityfocus.com/bid/99604 | vdb entry third party advisory |
http://seclists.org/oss-sec/2017/q3/521 | mailing list third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7535 | issue tracking third party advisory |