A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-09-12T15:14:29.533Z

Updated: 2024-08-02T05:02:43.579Z

Reserved: 2023-01-09T13:23:29.547Z

Link: CVE-2023-0119

cve-icon Vulnrichment

Updated: 2024-08-02T05:02:43.579Z

cve-icon NVD

Status : Modified

Published: 2023-09-12T16:15:08.007

Modified: 2024-05-03T16:15:09.563

Link: CVE-2023-0119

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-12T00:00:00Z

Links: CVE-2023-0119 - Bugzilla