A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2024-4812 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2280187 | third party advisory issue tracking |