An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-09-25T22:59:16

Updated: 2024-08-05T21:28:55.736Z

Reserved: 2019-09-25T00:00:00

Link: CVE-2017-18635

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-25T23:15:09.937

Modified: 2022-04-06T17:54:34.933

Link: CVE-2017-18635

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-01-12T00:00:00Z

Links: CVE-2017-18635 - Bugzilla