Project

General

Profile

Actions

Bug #20963

closed

CVE-2017-7535: stored XSS in the manage organization page

Added by Tomer Brisker about 7 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Low
Assignee:
Category:
Security
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

Attempting to assign all hosts to an organization or location that contains HTML does not properly escape the html in the toast notification informing of success.
Setting priority to low since exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

Actions #1

Updated by The Foreman Bot about 7 years ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/4851 added
Actions #2

Updated by Daniel Lobato Garcia about 7 years ago

  • Translation missing: en.field_release set to 240
Actions #3

Updated by Anonymous about 7 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions

Also available in: Atom PDF