CVE-2015-1368
Ansible Tower <2.0.5 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.
Exploits (1)
References (12)
Scores
EPSS
0.1401
EPSS Percentile
94.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
ansible/tower
< 2.0.2
Timeline
Published
Jan 27, 2015
Tracked Since
Feb 18, 2026