Stored Cross-Site Scripting Vulnerability in CloudForms by Red Hat
CVE-2019-10177
6.5MEDIUM
What is CVE-2019-10177?
A stored cross-site scripting vulnerability exists within the PDF export component of CloudForms versions 5.9 and 5.10. This flaw arises because user input is not adequately sanitized, allowing attackers with minimal privileges to edit compute resources to launch XSS attacks against other users. Such exploitation may lead to the execution of malicious code and the unauthorized extraction of anti-CSRF tokens, potentially compromising the security of higher-privileged users.
Affected Version(s)
CloudForms 5.9, 5.10