CVE-2017-15100
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/11/2017
Last modified:
20/04/2025
Description
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a such fact; (3) Statistics page, for facts that are aggregated on this page.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* | 1.16.0 (excluding) | |
cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:satellite_capsule:6.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page