CVE-2017-15100
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts pa
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart.
(2) Trends page, when checking the graph for a trend based on a such fact.
(3) Statistics page, for facts that are aggregated on this page.
MEDIUM · CVSS 6.1
EPSS 0.00343
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0