← back
CVE-2011-2927

Spacewalk: spacewalk and red hat network satellite: cross-site scripting vulnerability via search forms

CVSS 5.4 MEDIUMEPSS 1.5%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Feb 2014Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →