CVE-2019-11881

MEDIUM

Rancher <2.2.4 - XSS

Title source: llm

Description

A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary content, filtering tags but not special characters or symbols. There's no other limitation of the message, allowing malicious users to lure legitimate users to visit phishing sites with scare tactics, e.g., displaying a "This version of Rancher is outdated, please visit https://malicious.rancher.site/upgrading" message.

Exploits (1)

nomisec WORKING POC 3 stars
by MauroEldritch · poc
https://github.com/MauroEldritch/VanCleef

Scores

CVSS v3 4.7
EPSS 0.0544
EPSS Percentile 90.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Details

Status published
Products (2)
rancher/rancher 0Go
suse/rancher 2.1.4
Published Jun 10, 2019
Tracked Since Feb 18, 2026