Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4929 | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versions may be vulnerable contains a Cross Site Scripting (XSS) vulnerability in cobbler-web that can result in Privilege escalation to admin.. This attack appear to be exploitable via "network connectivity". Sending unauthenticated JavaScript payload to the Cobbler XMLRPC API (/cobbler_api). |
Github GHSA |
GHSA-q9g5-98pm-w6q7 | Cobbler XSS Vulnerability |
Ubuntu USN |
USN-6475-1 | Cobbler vulnerabilities |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:40:46.680Z
Reserved: 2018-08-02T00:00:00.000Z
Link: CVE-2018-1000225
No data.
Status : Modified
Published: 2018-08-20T20:29:01.720
Modified: 2026-06-17T01:32:42.993
Link: CVE-2018-1000225
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD
Github GHSA
Ubuntu USN