Cross-Site Scripting Vulnerabilities in OpenStack Dashboard (Horizon) by OpenStack
CVE-2013-6858

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
23 November 2013

Summary

OpenStack Dashboard (Horizon) versions 2013.2 and earlier are vulnerable to multiple cross-site scripting (XSS) flaws. These vulnerabilities enable local users to execute arbitrary web scripts or inject HTML content by manipulating instance names within the 'Volumes' or 'Network Topology' pages. This could potentially allow attackers to perform various malicious actions, disrupting user experience and leading to significant security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.