CVE-2019-10177 Information

Description

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms versions 5.9 and 5.10 due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users which could lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Reference

http://www.securityfocus.com/bid/109065 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10177

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

6.5

Share on: