CVE Published: 12/09/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: redhat |
Vendor: |
Product: Status : PUBLISHED
CVE-2023-0119 Description
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user\'s session, make requests on behalf of the user, and obtain user credentials.