5.4
CVSSv3

CVE-2018-14664

Published: 12/10/2018 Updated: 14/05/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

theforeman foreman 1.18.0

Vendor Advisories

Synopsis Moderate: Satellite 65 Release Type/Severity Security Advisory: Moderate Topic Red Hat Satellite 65 for RHEL 7 is now available containing security fixes, bug fixes, and enhancementsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Sco ...
A cross-site scripting (XSS) flaw was found in the foreman component of satellite An attacker with privilege to create entries using the Hosts, Monitor, Infrastructure, or Administer Menus is able to execute a XSS attacks against other users, possibly leading to malicious code execution and extraction of the anti-CSRF token of higher privileged us ...