Cross-Site Scripting Vulnerability in Migration-Planner by Red Hat
CVE-2026-53472
6.3MEDIUM
What is CVE-2026-53472?
A notable flaw has been identified in the migration-planner product by Red Hat. This issue stems from inadequate validation of the 'AgentStatusUpdate.CredentialUrl' field. As a result, an authenticated attacker can exploit this vulnerability by inserting a malicious 'javascript:' URL. When unsuspecting users interact with this URL in the Hybrid Cloud Console, it can trigger Cross-Site Scripting (XSS) attacks. Such attacks enable unauthorized script execution during a user’s session, which may lead to the exposure of sensitive user data.
