Impact
An unauthenticated endpoint allows a remote attacker to modify public UI settings, resulting in stored cross‑site scripting attacks. The attacker can inject malicious JavaScript that will execute in the browser context of any user who views the Rancher UI, enabling session hijacking, credential theft, or further lateral movement.
Affected Systems
The vulnerability affects SUSE Rancher versions 2.15 prior to 2.15.2, 2.14 prior to 2.14.6, 2.13 prior to 2.13.10, 2.12 prior to 2.12.14, and 2.11 prior to 2.11.18.
Risk and Exploitability
The CVSS score of 9.6 classifies it as critical. Although EPSS data is not available, the lack of listing in the CISA KEV catalog does not diminish the potential impact. Remote attackers can exploit the flaw without authentication by sending specially crafted requests to update UI settings, after which the injected script is persisted and executed whenever the settings are rendered in the UI.
OpenCVE Enrichment