Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-15125
HistoryJul 27, 2018 - 3:29 p.m.

Cross site scripting

2018-07-2715:29:00
PRIOn knowledge base
www.prio-n.com
6

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.9%

A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of this XSS however not all browsers support CSP.

CPENameOperatorVersion
cloudforms_management_enginelt5.9.0.22

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.9%

Related for PRION:CVE-2017-15125