Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | <= 1.4.4 |
Related Weaknesses (CWE)
References
- http://projects.theforeman.org/issues/6149ExploitPatch
- http://projects.theforeman.org/issues/6149ExploitPatch
FAQ
What is CVE-2014-3492?
CVE-2014-3492 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (...
How severe is CVE-2014-3492?
CVE-2014-3492 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3492?
Check the references section above for vendor advisories and patch information. Affected products include: Theforeman Foreman.