Impact
An unauthenticated client can submit data to the inventory service endpoint, which persists the input without sanitization. The Host Management Inventory page then renders all static inventory fields into HTML without output encoding, enabling stored cross‑site scripting that executes in the context of any administrator’s browser. This type of flaw, identified as CWE‑79, permits an attacker to run arbitrary script, potentially hijacking sessions, defacing content, or exfiltrating credentials.
Affected Systems
FOGProject’s open‑source cloning and inventory platform is affected in all releases older than version 1.5.10.1832 and version 1.6.0‑beta.2313. The vulnerability exists in the standard deployment of FOGProject with the default web configuration and does not require specific operating system or database versions.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1 % suggests a low probability of current exploitation, yet the attack can be carried out without authentication and only requires an administrator to open the infected page. The vulnerability is not listed in CISA’s KEV catalog. An attacker can inject JavaScript into /service/inventory.php, and it will be reflected when any privileged user views the Host Management page, producing a significant risk to confidentiality, integrity, and availability of the administrative session.
OpenCVE Enrichment