CVE-2023-49453
Description
From CVE.org
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.
Statement
This vulnerability doesn't affect any supported Red Hat products.
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability
Technical Impact: Read Application Data; Execute Unauthorized Code or Commands
An attacker could insert special characters that are processed client-side in the context of the user's session.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.