PT-2026-79324 · Apache · Cloudstack
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache CloudStack versions 4.15.1.0 through 4.20.3.0
Apache CloudStack versions 4.21.0.0 through 4.22.1.0
Description
Improper encoding or escaping of output in the user interface occurs when using the Instance Reset Password functionality. This leads to a Cross-Site Scripting (XSS) issue, where malicious scripts can be injected into web pages viewed by other users.
Recommendations
Upgrade Apache CloudStack versions 4.15.1.0 through 4.20.3.0 to version 4.20.3.1 or later.
Upgrade Apache CloudStack versions 4.21.0.0 through 4.22.1.0 to version 4.22.1.1 or later.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudstack