CVE-2013-6858
Openstack Horizon < 2013.2 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
References (6)
Scores
EPSS
0.0048
EPSS Percentile
64.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (5)
openstack/horizon
< 2013.2
opensuse/opensuse
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
Timeline
Published
Nov 23, 2013
Tracked Since
Feb 18, 2026