Vulnerabilities
Vulnerable Software
Theforeman:  >> Foreman  >> 1.13.1  Security Vulnerabilities
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
CVSS Score
6.1
EPSS Score
0.011
Published
2017-11-27
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
CVSS Score
6.1
EPSS Score
0.01
Published
2017-09-25
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object outside of their scope, such as editing global admin accounts including changing their passwords.
CVSS Score
8.8
EPSS Score
0.016
Published
2017-05-26


Contact Us

Shodan ® - All rights reserved