Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43760
HistoryJun 01, 2023 - 1:15 p.m.

Cross site scripting

2023-06-0113:15:00
PRIOn knowledge base
www.prio-n.com
8
cross-site scripting
suse rancher
input neutralization
web page generation
higher-privileged groups
vulnerability
sensitive information
web content manipulation
malicious activities
administrator access

8.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.3%

An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in SUSE Rancher allows users in some higher-privileged groups to to inject code that is
executed within another user’s browser, allowing the attacker to steal
sensitive information, manipulate web content, or perform other
malicious activities on behalf of the victims. This could result in a
user with write access to the affected areas being able to act on behalf
of an administrator, once an administrator opens the affected web page.

This issue affects Rancher: from >= 2.6.0 before < 2.6.13, from >= 2.7.0 before < 2.7.4.

8.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.3%

Related for PRION:CVE-2022-43760