A stored Cross-site scripting... CVE-2023-0119

- AV AC AU C I A
发布: 2023-09-12
修订: 2023-11-07

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息