A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Suse Container_Suse_Manager_5.0
cpe:2.3:a:suse:container_suse_manager_5.0:*:*:*:*:*:*:*:*
|
0
|
5.0.28-150600.3.36.8
|
|
Suse Suse_Manager_Server_Lts_4.3
cpe:2.3:a:suse:suse_manager_server_lts_4.3:*:*:*:*:*:*:*:*
|
0
|
4.3.88-150400.3.113.5
|