PT-2017-5778 · Foreman · Foreman

Jan Hutaå

·

Published

2017-10-16

·

Updated

2023-02-13

·

CVE-2014-0208

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Foreman versions prior to 1.4.4
Description: A cross-site scripting (XSS) issue exists in the search auto-completion functionality, allowing remote authenticated users to inject arbitrary web script or HTML via a crafted key name.
Recommendations: For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2014-0208

Affected Products

Foreman