Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Katello: potential cross-site scripting exploit in ui
Vulnerability Description
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Collections.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Katello 跨站脚本漏洞
Vulnerability Description
Katello是一款系统管理引擎。该产品可提供配置管理、订阅管理和内容管理的工作流。 Foreman Katello存在跨站脚本漏洞,该漏洞源于 Description 字段可以进行存储型跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A