cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10854.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.9"
}
]
}
]