CVE-2023-0119

Source
https://cve.org/CVERecord?id=CVE-2023-0119
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0119.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-0119
Downstream
Published
2023-09-12T16:15:08.007Z
Modified
2026-03-15T14:49:04.062195Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0119.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "6.13"
            }
        ]
    }
]