CVE-2018-1000225
MEDIUMCobbler 2.0.0+ - Unauthenticated Stored Cross-Site Scripting via XMLRPC API
Title source: llmDescription
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. This attack appear to be exploitable via "network connectivity". Sending unauthenticated JavaScript payload to the Cobbler XMLRPC API (/cobbler_api).
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/cobbler/cobbler/issues/1917
Third Party Advisory x_refsource_misc
https://movermeyer.com/2018-08-02-privilege-escalation-exploits-in-cobblers-api/
Scores
CVSS v3
6.1
EPSS
0.0126
EPSS Percentile
66.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
cobblerd/cobbler
pypi/cobbler
0PyPI
Published
Aug 20, 2018
Tracked Since
Feb 18, 2026