← Back to CVE List

CVE-2023-0119

Published: 2023-09-12T16:15Z
Last Modified: 2024-11-21T07:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt