Medium severity6.1NVD Advisory· Published Jul 26, 2018· Updated Jun 17, 2026
CVE-2017-7535
CVE-2017-7535
Description
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*range: <1.16.0
- (no CPE)range: 1.16.0
Patches
Vulnerability mechanics
References
4- seclists.org/oss-sec/2017/q3/521nvdMailing ListPatchThird Party Advisory
- www.securityfocus.com/bid/99604nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- projects.theforeman.org/issues/20963nvdVendor Advisory
News mentions
0No linked articles in our index yet.