CVE-2015-7518 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters (2) smart class parameters or (3) smart variables in the (a) host or (b) hostgroup edit forms.
Reference
http://projects.theforeman.org/issues/12611 http://theforeman.org/security.html2015-7518 http://www.openwall.com/lists/oss-security/2015/12/09/6 https://access.redhat.com/errata/RHSA-2016:0174
Share on: