Impact
An unauthenticated remote attacker can exploit a DOM Cross‑Site Scripting flaw in the FreeIPA/IdM Web UI password reset page. By delivering a specially crafted link to a victim, the attacker injects and runs arbitrary JavaScript within the victim’s authenticated session. This allows the attacker to perform a wide range of actions on the target system, potentially gaining full administrative control if a privileged account is targeted. The weakness is a typical Reflected or Stored XSS, classified as CWE‑79.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6, 7, 8, 9, and 10 that run FreeIPA/IdM with the Web UI component. Administrators using the password reset feature on any of these platforms are susceptible.
Risk and Exploitability
The CVSS score of 8.1 categorizes this flaw as High severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the impact remains significant because the attacker only needs to entice a password‑reset action from a victim. The likely attack vector is an HTTP(S) request to the affected page; the attacker must craft a malicious URL delivered via email or other social‑engineering channels. Once a user completes the reset, the injected script executes in the context of the victim’s session, potentially escalating privileges.
OpenCVE Enrichment