VYPR
Unrated severityNVD Advisory· Published Sep 12, 2023· Updated Aug 2, 2024

Foreman: stored cross-site scripting in host tab

CVE-2023-0119

Description

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.