ZeroHour

CVE-2016-4428

CVSS 3.1
5.4 medium
EPSS
2%p80
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

Vendors
openstackredhatdebian
Products
horizon, openstack, debian linux
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.