PT-2026-62080 · Fogproject · Fogproject

CVE-2026-47687

·

Published

2026-07-21

·

Updated

2026-08-07

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FOG versions prior to 1.5.10.1832 FOG versions prior to 1.6.0-beta.2313
Description The selectForm() function in fogpage.class.php renders labels using raw, unescaped user input. An unauthenticated attacker with knowledge of a registered host's MAC address can send a malicious sysproduct value to the '/service/inventory.php' endpoint. This value is stored in the database and, when an administrator accesses the Reports > Inventory section, the payload executes arbitrary JavaScript in the administrator's browser.
Recommendations Update to version 1.5.10.1832. Update to version 1.6.0-beta.2313.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47687

Affected Products

Fogproject