VYPR
Medium severity5.4NVD Advisory· Published Nov 22, 2019· Updated Jun 17, 2026

CVE-2018-10854

CVE-2018-10854

Description

cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:redhat:cloudforms_management_engine:4.7:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:cloudforms_management_engine:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:cloudforms_management_engine:5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:cloudforms_management_engine:5.9:*:*:*:*:*:*:*
  • Red Hat/Cloudformsllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: cloudforms 5.8 and cloudforms 5.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.