CVE Published: 04/10/2023 |
CVE Updated: 23/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: Red Hat |
Product: Red Hat Ansible Automation Platform 2.3 for RHEL 8 Status : PUBLISHED
CVE-2023-3971 Description
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.