CVE-2017-7535: stored XSS in the manage organization page
|Assigned To:||Tomer Brisker|
|Found in release:||1.1||Pull request:||https://github.com/theforeman/foreman/pull/4851|
|Velocity based estimate||-|
Attempting to assign all hosts to an organization or location that contains HTML does not properly escape the html in the toast notification informing of success.
Setting priority to low since exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.