CVE-2023-0119
12.09.2023, 16:15
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
Vendor | Product | Version |
---|---|---|
redhat | satellite | 6.13 |
𝑥
= Vulnerable software versions
References