VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
BID:100844
CVE-2017-4926 |Info
VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
| Bugtraq ID: | 100844 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-4926 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2017 12:00AM |
| Updated: | Sep 15 2017 07:14PM |
| Credit: | Thomas Ornetzeder. |
| Vulnerable: |
VMWare vCenter Server 6.5 |
| Not Vulnerable: |
VMWare vCenter Server 6.5 U1 |
Discussion
VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
VMware vCenter Server is prone to an HTML injection vulnerability because it fails to sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
VMware vCenter Server 6.5 is vulnerable; other versions may also be affected.
VMware vCenter Server is prone to an HTML injection vulnerability because it fails to sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
VMware vCenter Server 6.5 is vulnerable; other versions may also be affected.
Exploit / POC
VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
VMware vCenter Server CVE-2017-4926 HTML Injection Vulnerability
References:
References: