Vulnerability CVE-2023-0119


Published: 2023-09-12   Modified: 2023-09-13

Description:
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.

 References:
https://bugzilla.redhat.com/show_bug.cgi?id=2159104
https://access.redhat.com/errata/RHSA-2023:3387
https://access.redhat.com/security/cve/CVE-2023-0119

Copyright 2026, cxsecurity.com

 

Back to Top