CVE-2014-3491

Foreman < 1.4.4 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.

Scores

EPSS 0.0032
EPSS Percentile 54.6%

Details

CWE
CWE-79
Status published
Products (7)
theforeman/foreman < 1.4.4
theforeman/foreman
theforeman/foreman
theforeman/foreman
theforeman/foreman
theforeman/foreman
n/a/n/a
Published Jul 01, 2014
Tracked Since Feb 18, 2026